content-research
Pass
Audited by Gen Agent Trust Hub on May 2, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external web sources such as social media posts, community forums, and advertising libraries. This presents an inherent surface for indirect prompt injection, where malicious instructions hidden in the researched content could attempt to manipulate the agent's behavior. The skill mitigates this by employing a structured multi-agent pipeline and a specialized 'critic-agent' to validate data quality and adherence to guidelines.
- [EXTERNAL_DOWNLOADS]: The skill leverages web search and fetching tools to access information from well-known technology companies and services, including Meta, TikTok, LinkedIn, Google, and Reddit. These external references are restricted to data gathering for research purposes and do not involve the execution of remote scripts or the installation of unverified software.
- [COMMAND_EXECUTION]: While the skill manifest requests access to the
Bashtool, no executable scripts or dangerous shell commands were found in the instructions. The tool appears to be intended for standard orchestration and file handling within the agent's environment.
Audit Metadata