research-service
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8). It instructs the agent to gather data from external sources including web searches and AWS Lambda packages. This data is used to generate architectural recommendations without sufficient protection against embedded instructions.
- Ingestion points: Data enters via
web_search,web_fetch, andaws lambda get-function. - Boundary markers: No delimiters or explicit instructions to ignore embedded commands are defined.
- Capability inventory: Access to shell commands (
bash,curl,unzip,grep), package management (dotnet), and Python script execution (boto3). - Sanitization: No evidence of validation or filtering of external content.
- [EXTERNAL_DOWNLOADS]: The skill performs remote downloads and package management. It fetches Lambda code via
curland installs library dependencies usingdotnet add packagefrom well-known official registries and AWS services. - [COMMAND_EXECUTION]: The skill executes multiple shell and environment-based commands for verification. It uses
grepto inspect local NuGet cache paths and runs Python scripts to inspectboto3client capabilities.
Audit Metadata