research

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from web search results and GitHub repository content, creating a surface for indirect prompt injection. This is expected behavior for a research-oriented skill.
  • Ingestion points: Data is gathered via the WebSearch tool and the docs-seeker skill.
  • Boundary markers: There are no explicit delimiters used to separate fetched content from internal instructions during the analysis phase.
  • Capability inventory: The skill has permissions to write files to the ./plans/ directory and execute the gemini bash CLI tool.
  • Sanitization: External content is not explicitly sanitized before being incorporated into the report or processed by the local CLI tool.
  • [COMMAND_EXECUTION]: The skill executes the gemini bash command using dynamically generated search prompts. While this involves command line execution, it is the primary method for the skill's data synthesis and is used within its intended scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — research