research
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to perform external research by retrieving and synthesizing data from web sources. This functionality introduces a surface for indirect prompt injection, where malicious instructions embedded in third-party web content or documentation could be processed by the agent.
- Ingestion points: External web sources, primary documents, and release notes referenced in the research workflow (SKILL.md).
- Boundary markers: Absent. The skill does not provide specific instructions or delimiters to the agent to treat external content as untrusted data or to ignore embedded instructions.
- Capability inventory: Information retrieval, synthesis, and citation generation based on external inputs (SKILL.md).
- Sanitization: Absent. There are no requirements or logic for validating, escaping, or filtering content retrieved from the web before it is incorporated into the agent's response.
Audit Metadata