brave-search

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves content from external websites via the Brave Search API, which introduces a surface for indirect prompt injection where malicious instructions could be embedded in search results.
  • Ingestion points: brave_search.py in the web_search and local_search functions which fetch third-party web snippets.
  • Boundary markers: Absent; the skill returns raw result strings without additional delimiters or instruction-bypass warnings.
  • Capability inventory: The skill scripts do not contain dangerous capabilities such as arbitrary subprocess execution, file writing, or system modification based on the ingested data.
  • Sanitization: Absent; web content (titles and descriptions) is passed through to the agent without filtering or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — brave-search