research-ops
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied evidence and local context which could potentially contain malicious instructions. However, it incorporates logical safeguards by explicitly instructing the agent to categorize and label information types.
- Ingestion points: Processes user-supplied evidence and local context as described in SKILL.md.
- Boundary markers: The skill mandates the use of explicit evidence boundaries (sourced facts, user-provided context, inference, recommendation) in both the workflow and output format sections.
- Capability inventory: This skill serves as an instruction-based wrapper and does not contain direct command execution, file-write, or network operations itself; it orchestrates other existing tools.
- Sanitization: No technical sanitization is implemented, but the logical separation of context acts as a mitigation against following embedded instructions.
Audit Metadata