research-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that processes untrusted external discovery data and user-provided evidence, creating a potential surface for indirect prompt injection. However, it incorporates safety best practices to mitigate this risk.
  • Ingestion points: Ingests data from external discovery tools like 'exa-search' and 'deep-research', as well as 'user-provided evidence' (SKILL.md).
  • Boundary markers: Present; the instructions explicitly direct the agent to separate 'sourced facts', 'user-provided context', 'inference', and 'recommendation' in the output format (SKILL.md).
  • Capability inventory: Orchestrates search, synthesis, ranking, and context storage tools (SKILL.md).
  • Sanitization: The workflow requires normalization and verification of supplied material before use (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — research-ops