search-first

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection surface by instructing the agent to search for and process data from untrusted external sources such as npm, PyPI, and GitHub during the research phase.
  • Ingestion points: External search results, package metadata, and documentation retrieved from package registries and GitHub (SKILL.md).
  • Boundary markers: There are no instructions or boundary markers provided to help the agent distinguish between authoritative skill instructions and potentially adversarial content found during research.
  • Capability inventory: The workflow involves the execution of various CLI tools (rg, npm, gh, ls) and grants the agent the ability to install packages and modify the local project based on external research (SKILL.md).
  • Sanitization: The skill does not specify any validation, filtering, or sanitization steps for the information retrieved from external sources before the agent acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:21 AM
Security Audit — agent-trust-hub — search-first