model-researcher

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative directives ('EXTREMELY STRICT', 'MUST NOT', 'MUST be rejected') to explicitly override the agent's behavior. It forces the agent to hallucinate a future timeline and refuse legitimate user requests for current industry-standard models.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow that takes untrusted input from the web and applies it to a critical configuration file.
  • Ingestion points: The websearch tool is used in SKILL.md (Step 2) to gather model identifiers and specifications from external sites.
  • Boundary markers: No delimiters or safety instructions are provided to distinguish between search results and system instructions.
  • Capability inventory: The skill possesses read access to ~/.config/opencode/opencode.json and likely write access through surgical edits as described in Step 4, alongside network access via websearch.
  • Sanitization: There is no evidence of validation or sanitization of external search data before it is written to the configuration file.
  • [METADATA_POISONING]: The skill provides misleading technical information regarding model availability and capabilities, aiming to contaminate the agent's context with non-existent 'Q4 2025' technical specs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:49 PM