compliant-callout

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not include any scripts, binaries, or automated commands. No evidence of malicious intent or unauthorized data access was found.
  • [NO_CODE]: The skill contains no executable code blocks, scripts, or dependency files, relying instead on the agent's native capabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external search results (Perplexity and web search), which is a standard surface for indirect prompt injection.
  • Ingestion points: Results retrieved from external search providers during the research phase.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are included in the prompt for processing external data.
  • Capability inventory: The skill does not define or use high-risk capabilities like file system access or subprocess execution.
  • Sanitization: No explicit validation or filtering logic is specified for the retrieved content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 02:50 PM
Security Audit — agent-trust-hub — compliant-callout