deep-research

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a behavioral workflow that presents an indirect prompt injection surface. Ingestion points: Workflow Step 2 (Identify and Gather Sources) and Step 3 (Extract and Organize Key Findings) instruct the agent to read and process data from various external web sources. Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instruction' warnings for the data being processed. Capability inventory: The skill's functionality is limited to report synthesis and narrative generation; it does not define capabilities for file-system modification or network operations. Sanitization: There are no procedures defined for sanitizing or validating external content before it is incorporated into the agent's context.
  • [NO_CODE]: The skill is composed entirely of markdown documentation and behavioral guidelines. It does not include any executable scripts, binaries, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 07:16 AM
Security Audit — agent-trust-hub — deep-research