search-first

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill encourages searching for and adopting third-party libraries from established registries such as npm, PyPI, and GitHub. This activity is a core component of the described research workflow and targets well-known services.- [COMMAND_EXECUTION]: Instructions include the use of standard development tools like rg (ripgrep) for local code searching and package managers for dependency installation. These operations are consistent with the skill's stated objective of integrating existing solutions into a project.- [PROMPT_INJECTION]: The 'Full Mode' workflow exposes a surface for indirect prompt injection by interpolating user-provided project descriptions and constraints directly into a subagent's prompt template.
  • Ingestion points: User-provided input variables ([DESCRIPTION], [LANG], [ANY]) in the researcher agent task configuration.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the prompt template.
  • Capability inventory: The agent is guided to search external registries and recommend package installations based on the processed input.
  • Sanitization: No sanitization or validation of the user-provided strings is performed before they are incorporated into the research prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:00 AM
Security Audit — agent-trust-hub — search-first