investigate

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via its research phase.\n
  • Ingestion points: WebSearch and WebFetch are used in protocols/research.md to collect data from the internet based on sub-problems.\n
  • Boundary markers: No delimiters or protective instructions are defined to isolate untrusted web content from the agent's internal logic.\n
  • Capability inventory: The skill can write files to the local system (targeting $THINKING_DIR in SKILL.md) and execute sub-agents using the Task tool.\n
  • Sanitization: External web content is synthesized into trade-off matrices and design decisions without validation or filtering.\n- [EXTERNAL_DOWNLOADS]: The skill performs automated data collection from external web services.\n
  • The Research protocol in protocols/research.md explicitly instructs the agent to utilize WebSearch and WebFetch to investigate solutions and patterns for identified technical challenges.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:18 AM
Security Audit — agent-trust-hub — investigate