deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites via the firecrawl and exa MCP tools. This content is then synthesized into research reports, which could allow malicious instructions embedded in web pages to influence the agent's behavior.
  • Ingestion points: Web content retrieved via firecrawl_search, firecrawl_scrape, web_search_exa, and crawling_exa.
  • Boundary markers: The skill uses markdown headers and source citations to structure output, but lacks specific delimiters or instructions to ignore embedded commands within the scraped content.
  • Capability inventory: The skill has capabilities to search the web, scrape full page content, and save synthesized reports to local files.
  • Sanitization: No explicit sanitization, escaping, or filtering of the retrieved web content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — deep-research