web-research
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches untrusted data from the web (search snippets and page content) and processes it using subagents to create a synthesized report. This creates a risk where malicious instructions on a webpage could influence the agent's behavior.
- Ingestion points: Web content retrieved via
WebSearchandWebFetchtools as described inSKILL.mdandreferences/failure-modes.md. - Boundary markers: Absent. The skill instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when subagents process fetched web content.
- Capability inventory: The skill performs file system writes (
plan.md,findings/*.md,report.md) and network operations via theWebSearchandWebFetchtools. - Sanitization: Absent. The skill explicitly requires subagents to capture 'verbatim excerpts' from pages without mention of escaping or filtering.\n- [PROMPT_INJECTION]: The
research_questioninput is interpolated verbatim into the orchestrator's and subagents' prompts (e.g., inplan.mdandreferences/subagent-brief.md). The skill explicitly states it 'does not reshape' or 'sharpen' the question, which may allow an attacker to embed instructions that override the skill's logic or the agent's safety guidelines.
Audit Metadata