research-ops
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a shell script
scripts/verify.shused to validate the structure and provenance of research memos. The script uses standard tools likeawk,grep, andsedto perform static text analysis on Markdown files. It is executed via the!syntax in theSKILL.md(e.g.,!./scripts/verify.sh --path memo.md). This is a benign use of shell capabilities for local linting and quality assurance of the skill's own output. - [REMOTE_CODE_EXECUTION]: No remote code execution patterns or package manager commands were detected. The skill relies on standard search and fetch capabilities typically available to agents but does not include instructions to download and execute external scripts.
- [DATA_EXFILTRATION]: While the skill involves fetching web pages for research purposes, it does not access sensitive local files (e.g.,
.ssh,.env) or attempt to send such data to external endpoints. The workflow is restricted to information gathering and memo synthesis. - [PROMPT_INJECTION]: The instructions do not attempt to bypass safety filters or override agent constraints. Instead, they enforce a methodology for factual accuracy and source verification.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web (Cat 8c). However, it explicitly mitigates this risk through a rigorous 'Source Credibility' rubric (SIFT/CRAAP) and a mandatory requirement to triangulate claims across at least two independent sources. The
verify.shscript acts as a structural gate, though it does not perform content sanitization.
Audit Metadata