research-service

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8). It instructs the agent to gather data from external sources including web searches and AWS Lambda packages. This data is used to generate architectural recommendations without sufficient protection against embedded instructions.
  • Ingestion points: Data enters via web_search, web_fetch, and aws lambda get-function.
  • Boundary markers: No delimiters or explicit instructions to ignore embedded commands are defined.
  • Capability inventory: Access to shell commands (bash, curl, unzip, grep), package management (dotnet), and Python script execution (boto3).
  • Sanitization: No evidence of validation or filtering of external content.
  • [EXTERNAL_DOWNLOADS]: The skill performs remote downloads and package management. It fetches Lambda code via curl and installs library dependencies using dotnet add package from well-known official registries and AWS services.
  • [COMMAND_EXECUTION]: The skill executes multiple shell and environment-based commands for verification. It uses grep to inspect local NuGet cache paths and runs Python scripts to inspect boto3 client capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — research-service