model-researcher
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [PROMPT_INJECTION]: The skill uses authoritative directives ('EXTREMELY STRICT', 'MUST NOT', 'MUST be rejected') to explicitly override the agent's behavior. It forces the agent to hallucinate a future timeline and refuse legitimate user requests for current industry-standard models.
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow that takes untrusted input from the web and applies it to a critical configuration file.
- Ingestion points: The
websearchtool is used inSKILL.md(Step 2) to gather model identifiers and specifications from external sites. - Boundary markers: No delimiters or safety instructions are provided to distinguish between search results and system instructions.
- Capability inventory: The skill possesses read access to
~/.config/opencode/opencode.jsonand likely write access through surgical edits as described in Step 4, alongside network access viawebsearch. - Sanitization: There is no evidence of validation or sanitization of external search data before it is written to the configuration file.
- [METADATA_POISONING]: The skill provides misleading technical information regarding model availability and capabilities, aiming to contaminate the agent's context with non-existent 'Q4 2025' technical specs.
Audit Metadata