deep-research

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its core research functionality.
  • Ingestion points: External data is ingested via the WebFetch tool (Step 2) and read from local source maps (Step 1).
  • Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" warnings when processing the fetched web content.
  • Capability inventory: The skill has access to Write for file operations and Bash for command execution.
  • Sanitization: No sanitization or validation of the external web content is specified before processing or reporting.
  • [COMMAND_EXECUTION]: The skill is granted Bash tool access. Although the instructions describe research and file operations rather than specific shell commands, the capability remains available for potential use.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 09:18 AM
Security Audit — agent-trust-hub — deep-research