research
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by directing the agent to ingest and summarize data from external primary sources.
- Ingestion points: The agent is instructed to read official docs, source code, specs, and APIs (referenced in SKILL.md).
- Boundary markers: Absent. There are no instructions to use delimiters or ignore instructions that may be embedded within the researched material.
- Capability inventory: The agent has the capability to write findings to the local filesystem (e.g., in
.specs/research/). - Sanitization: Absent. The skill does not define any validation or sanitization requirements for the external content before it is written to the repository.
- [NO_CODE]: The skill consists entirely of natural language instructions in SKILL.md and does not ship with any executable scripts, binaries, or configuration files.
Audit Metadata