web-research
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues or malicious patterns were identified. The skill implements a robust workflow with user oversight. 1. Ingestion points: External data is fetched via standard search and fetch tools as described in SKILL.md and subagent-brief.md. 2. Boundary markers: Data is structured into findings files to maintain context, though no explicit isolation delimiters are used for the raw web excerpts. 3. Capability inventory: Actions are restricted to file creation, reading, and tool execution within specified research directories. 4. Sanitization: Verbatim quoting and citation requirements provide a verifiable trail of all external inputs, reducing the impact of potential indirect prompt injection. 5. File System: Absolute path handling is mitigated by explicit re-run protection and archiving logic that preserves audit trails.
Audit Metadata