research

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard shell utilities such as git and sed to resolve the project root and efficiently read specific sections of local research files without loading the entire document into context. These operations are scoped to the project's .research/ directory.
  • [PROMPT_INJECTION]: As a tool designed to ingest external web content and user-pasted documents, the skill possesses a surface for indirect prompt injection. This is an inherent risk for any research or RAG (Retrieval-Augmented Generation) system. The skill mitigates this through structured storage schemas and explicit subagent briefing instructions that prioritize synthesis over direct citation.
  • [SAFE]: Analysis of the skill's instructions, metadata, and development history (CHANGELOG.md) indicates a legitimate, transparent purpose. The developer has proactively addressed previous security scanner concerns (e.g., removing 'silent' framing from setup steps) and follows best practices for project-level data isolation and privacy.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 11:55 PM
Security Audit — agent-trust-hub — research