research
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from primary sources (documentation, code, APIs) which could contain malicious instructions designed to influence the agent's behavior during the research process.
- Ingestion points: External content retrieved from web-based documentation and source code repositories specified in
SKILL.md. - Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore instructions embedded within the research material.
- Capability inventory: The agent possesses the capability to write markdown files to the local repository as described in
SKILL.md. - Sanitization: No sanitization or validation logic is defined to prevent the propagation of malicious payloads from the source material into the generated repository files.
Audit Metadata