tech-stack-research
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
WebSearchandWebFetchto retrieve information from external websites. This is the core functionality for researching technical options, benchmarks, and community health. - [PROMPT_INJECTION]: The instructions use emphatic, repetitive language (e.g., 'MANDATORY IMPORTANT MUST ATTENTION') to enforce a strict workflow. This is intended to ensure task breakdown, user interaction, and evidence-based reporting, rather than attempting to bypass safety filters or extract system prompts.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from web searches and local artifacts, creating a potential surface for indirect injection if that data contains malicious instructions.
- Ingestion points: External content from
WebFetchand local business context files inplans/andteam-artifacts/. - Boundary markers: Not explicitly defined for external content.
- Capability inventory: The skill has access to
Bash,Write, andEdittools. - Sanitization: No explicit sanitization or instruction-filtering logic is present for the ingested data.
Audit Metadata