research-it

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted data from external sources via tools like WebFetch.
  • Ingestion points: External documentation and primary references fetched during the "Search inward then outward" phase in SKILL.md.
  • Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore instructions found within external content.
  • Capability inventory: The skill can trigger subagents, create issues (issues create), and perform repository surveys.
  • Sanitization: No explicit sanitization or filtering of external content is described.
  • [EXTERNAL_DOWNLOADS]: The skill workflow involves fetching external documentation and reputable references using the WebFetch tool as described in the "Search inward then outward" section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — research-it