research-integration

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs subagents to perform high-risk operations including cloning external repositories via git clone and installing third-party dependencies through pip install or npm install based on technical artifacts discovered during web research.
  • [COMMAND_EXECUTION]: Research subagents are directed to execute Python analysis scripts against downloaded third-party codebases, SDKs, and schema files to extract structural data and field inventories.
  • [DYNAMIC_EXECUTION]: The skill generates a standalone Python script (test-api.py) for API testing based on discovered specifications and subsequently uses python3 -m py_compile to validate the generated code's syntax.
  • [EXTERNAL_DOWNLOADS]: The workflow involves extensive network activity to fetch user-provided documentation URLs and download large-scale technical artifacts, such as OpenAPI specifications and SDK source code, from the public internet.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from documentation pages and external repositories discovered at runtime.
  • Ingestion points: User-provided URLs (Phase 1) and subagent-discovered repositories/schemas (Tracks B and C).
  • Boundary markers: The skill uses separate subagent contexts with an operating manual (research-subagent-guidance.md), but lacks strict delimiters for processing ingested documentation content.
  • Capability inventory: Subagents possess write-access to the local filesystem, network access, and the ability to install and execute Python code.
  • Sanitization: There is no evidence of sanitization or filtering for the external content retrieved during the documentation fetch or repository analysis phases.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 10:03 PM
Security Audit — agent-trust-hub — research-integration