research-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that processes untrusted external discovery data and user-provided evidence, creating a potential surface for indirect prompt injection. However, it incorporates safety best practices to mitigate this risk.
- Ingestion points: Ingests data from external discovery tools like 'exa-search' and 'deep-research', as well as 'user-provided evidence' (SKILL.md).
- Boundary markers: Present; the instructions explicitly direct the agent to separate 'sourced facts', 'user-provided context', 'inference', and 'recommendation' in the output format (SKILL.md).
- Capability inventory: Orchestrates search, synthesis, ranking, and context storage tools (SKILL.md).
- Sanitization: The workflow requires normalization and verification of supplied material before use (SKILL.md).
Audit Metadata