research

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by directing the agent to ingest and summarize data from external primary sources.
  • Ingestion points: The agent is instructed to read official docs, source code, specs, and APIs (referenced in SKILL.md).
  • Boundary markers: Absent. There are no instructions to use delimiters or ignore instructions that may be embedded within the researched material.
  • Capability inventory: The agent has the capability to write findings to the local filesystem (e.g., in .specs/research/).
  • Sanitization: Absent. The skill does not define any validation or sanitization requirements for the external content before it is written to the repository.
  • [NO_CODE]: The skill consists entirely of natural language instructions in SKILL.md and does not ship with any executable scripts, binaries, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — research