deep-research
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill defines a behavioral workflow that presents an indirect prompt injection surface. Ingestion points: Workflow Step 2 (Identify and Gather Sources) and Step 3 (Extract and Organize Key Findings) instruct the agent to read and process data from various external web sources. Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instruction' warnings for the data being processed. Capability inventory: The skill's functionality is limited to report synthesis and narrative generation; it does not define capabilities for file-system modification or network operations. Sanitization: There are no procedures defined for sanitizing or validating external content before it is incorporated into the agent's context.
- [NO_CODE]: The skill is composed entirely of markdown documentation and behavioral guidelines. It does not include any executable scripts, binaries, or configuration files.
Audit Metadata