perplexity
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use tools that fetch content from the public internet, which may contain malicious instructions intended to manipulate the AI's behavior.
- Ingestion points: Data enters the agent's context through the output of
mcp__perplexity__perplexity_searchandmcp__perplexity__perplexity_askas described inREADME.mdandSKILL.md. - Boundary markers: The instructions lack specific guidance on using delimiters or system-level constraints to prevent the agent from obeying instructions found within search results.
- Capability inventory: While the skill itself consists only of documentation and does not provide its own executable scripts, the agent is expected to interact with web-based data which could influence its use of other capabilities.
- Sanitization: There are no requirements for sanitizing, filtering, or validating the content retrieved from external search queries before processing.
Audit Metadata