deep-research

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a legitimate research workflow and follows best practices for sourcing and attribution.
  • [PROMPT_INJECTION]: The skill exhibits surface area for indirect prompt injection as it ingests untrusted data from the public web. However, the risk is mitigated by the skill's limited capability set.
  • Ingestion points: Untrusted data enters the context via firecrawl_scrape and crawling_exa in Step 4.
  • Boundary markers: Absent. The skill instructions do not define specific delimiters or instructions to ignore embedded commands within crawled content.
  • Capability inventory: Capabilities are limited to web searching, scraping, and writing the final markdown report to a file. There are no subprocess execution, credential access, or arbitrary shell capabilities.
  • Sanitization: Absent. The skill does not describe any specific sanitization or filtering of external content before processing.
  • [DATA_EXFILTRATION]: No exfiltration patterns were found. Network activity is scoped to the primary purpose of the skill (web research) using dedicated tool interfaces.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:41 AM
Security Audit — agent-trust-hub — deep-research