deep-research

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches content from external web sources via Firecrawl and Exa MCP tools. These are well-known technology services utilized for their primary intended purpose of search and retrieval.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the open web, creating a surface for indirect prompt injection.
  • Ingestion points: Web content retrieved via firecrawl_search, firecrawl_scrape, web_search_exa, and crawling_exa in SKILL.md.
  • Boundary markers: Absent; instructions do not explicitly require wrapping retrieved content in delimiters.
  • Capability inventory: No dangerous capabilities detected; the skill utilizes read-only tool calls and lacks file-write or shell execution primitives.
  • Sanitization: Absent; no explicit instructions for filtering or escaping fetched web content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:56 PM
Security Audit — agent-trust-hub — deep-research