research
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from web search results and GitHub repository content, creating a surface for indirect prompt injection. This is expected behavior for a research-oriented skill.
- Ingestion points: Data is gathered via the
WebSearchtool and thedocs-seekerskill. - Boundary markers: There are no explicit delimiters used to separate fetched content from internal instructions during the analysis phase.
- Capability inventory: The skill has permissions to write files to the
./plans/directory and execute thegeminibash CLI tool. - Sanitization: External content is not explicitly sanitized before being incorporated into the report or processed by the local CLI tool.
- [COMMAND_EXECUTION]: The skill executes the
geminibash command using dynamically generated search prompts. While this involves command line execution, it is the primary method for the skill's data synthesis and is used within its intended scope.
Audit Metadata