web-research

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches untrusted data from the web (search snippets and page content) and processes it using subagents to create a synthesized report. This creates a risk where malicious instructions on a webpage could influence the agent's behavior.
  • Ingestion points: Web content retrieved via WebSearch and WebFetch tools as described in SKILL.md and references/failure-modes.md.
  • Boundary markers: Absent. The skill instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when subagents process fetched web content.
  • Capability inventory: The skill performs file system writes (plan.md, findings/*.md, report.md) and network operations via the WebSearch and WebFetch tools.
  • Sanitization: Absent. The skill explicitly requires subagents to capture 'verbatim excerpts' from pages without mention of escaping or filtering.\n- [PROMPT_INJECTION]: The research_question input is interpolated verbatim into the orchestrator's and subagents' prompts (e.g., in plan.md and references/subagent-brief.md). The skill explicitly states it 'does not reshape' or 'sharpen' the question, which may allow an attacker to embed instructions that override the skill's logic or the agent's safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — web-research