research
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze potentially untrusted data from external sources including web pages, social media threads (Reddit, HN, X), and customer transcripts.
- Ingestion points: Web search results, social media posts, and bulk user research raw material such as support tickets and reviews (
SKILL.md,references/market-pulse.md,references/user-research.md). - Boundary markers: The skill contains an explicit 'Untrusted-source guard' section in
SKILL.mdthat instructs the agent to never follow instructions found in a source and to treat fetched content as cited claims only. - Capability inventory: The agent has access to powerful tools including
bash,run_command, andwrite_to_file(SKILL.md,agents/openai.yaml). - Sanitization: The instructions provide a specific protocol to flag agent-directed text under its citation and require corroboration before findings reach the final report.
- [COMMAND_EXECUTION]: The skill distributes a local script,
scripts/sample-size.ts, which the agent is instructed to execute using thebashorrun_commandtools. This script performs mathematical calculations for research rigor (sample sizing and qualitative saturation). The script was analyzed and found to be a safe, self-contained utility that does not perform network operations or unsafe file access.
Audit Metadata