research-ops

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell script scripts/verify.sh used to validate the structure and provenance of research memos. The script uses standard tools like awk, grep, and sed to perform static text analysis on Markdown files. It is executed via the ! syntax in the SKILL.md (e.g., !./scripts/verify.sh --path memo.md). This is a benign use of shell capabilities for local linting and quality assurance of the skill's own output.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or package manager commands were detected. The skill relies on standard search and fetch capabilities typically available to agents but does not include instructions to download and execute external scripts.
  • [DATA_EXFILTRATION]: While the skill involves fetching web pages for research purposes, it does not access sensitive local files (e.g., .ssh, .env) or attempt to send such data to external endpoints. The workflow is restricted to information gathering and memo synthesis.
  • [PROMPT_INJECTION]: The instructions do not attempt to bypass safety filters or override agent constraints. Instead, they enforce a methodology for factual accuracy and source verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web (Cat 8c). However, it explicitly mitigates this risk through a rigorous 'Source Credibility' rubric (SIFT/CRAAP) and a mandatory requirement to triangulate claims across at least two independent sources. The verify.sh script acts as a structural gate, though it does not perform content sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — research-ops