researching

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions and associated template follow best practices for automated documentation. All file system and sub-agent operations are aligned with the stated purpose of research.- [PROMPT_INJECTION]: The skill ingests untrusted data from codebase files, creating a surface for indirect prompt injection. Ingestion occurs when reading user-specified or discovered files. While boundary markers and explicit sanitization are absent, the skill's capabilities are focused on writing documentation to the 'thoughts/' directory and spawning specialized sub-agents, which reduces the impact of potential exploits.- [EXTERNAL_DOWNLOADS]: The skill references external documentation retrieval via the context7 MCP and an optional web-search sub-agent. These are legitimate resources for comprehensive technical research.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 09:43 PM