brave-search
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves content from external websites via the Brave Search API, which introduces a surface for indirect prompt injection where malicious instructions could be embedded in search results.
- Ingestion points:
brave_search.pyin theweb_searchandlocal_searchfunctions which fetch third-party web snippets. - Boundary markers: Absent; the skill returns raw result strings without additional delimiters or instruction-bypass warnings.
- Capability inventory: The skill scripts do not contain dangerous capabilities such as arbitrary subprocess execution, file writing, or system modification based on the ingested data.
- Sanitization: Absent; web content (titles and descriptions) is passed through to the agent without filtering or escaping.
Audit Metadata