skills/itechmeat/llm-code/perplexity/Gen Agent Trust Hub

perplexity

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for tools (web_search, fetch_url_content) that retrieve data from external web sources, creating a surface for indirect prompt injection.
  • Ingestion points: Documentation in references/pro-search.md describes the automatic retrieval of web content.
  • Boundary markers: The skill suggests using system prompts for instructions, but the model remains susceptible to instructions embedded in the search results it processes.
  • Capability inventory: The skill uses the Perplexity API to perform network operations and search queries.
  • Sanitization: references/chat-completions.md advises validating files produced by the sandbox and treating retrieved content as untrusted.
  • [DYNAMIC_EXECUTION]: The skill documents the use of a built-in sandbox tool designed for code execution, which is a powerful capability that must be carefully managed.
  • Evidence: references/chat-completions.md details the 'Responses API sandbox' and subresources for file retrieval.
  • Mitigation: The documentation includes warnings to gate the tool by product policy and avoid exposing it to untrusted user input.
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the perplexityai Python library and the @perplexityai/perplexity Node.js package. These are standard dependencies for integrating with the Perplexity service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:24 AM