lead-research-assistant-cn
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches its instruction file from a public repository on GitHub, a well-known service, during the installation process.\n- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and process data from potentially untrusted external sources and the local project environment.\n
- Ingestion points: The agent is instructed to analyze the local repository's codebase (Step 1) and perform web searches for company data, job postings, and news (Step 3).\n
- Boundary markers: There are no explicit instructions or delimiters defined to separate user-provided or web-retrieved content from the agent's core instructions.\n
- Capability inventory: The skill leverages the agent's internal tools for reading file systems and executing web searches to perform its core research functions.\n
- Sanitization: The instructions do not include any steps for validating, escaping, or filtering the data retrieved from the web or the codebase before it is used for analysis.\n- [NO_CODE]: This skill consists exclusively of markdown instructions and metadata, with no accompanying scripts or executable code.
Audit Metadata