tech-selection-research
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill provides a legitimate research workflow with no evidence of obfuscation, malicious instructions, or persistence mechanisms.
- [COMMAND_EXECUTION]: The skill includes a local Python script for matrix calculations; this script is audited and performs only basic arithmetic on agent-provided JSON data.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests external data. (1) Ingestion points: WebSearch and WebFetch tools used for tech research. (2) Boundary markers: Explicit instructions to use a source hierarchy and label all evidence as 'Verified', 'Inference', or 'Needs PoC'. (3) Capability inventory: Execution of a local Python script and generation of markdown reports. (4) Sanitization: Mandatory prioritization of official documentation and critical evaluation of community feedback to filter unverified external content.
Audit Metadata