clicky-research-report

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes curl and browser automation (Cua/Computer Use) to perform web research. These are standard tools for the task and the skill includes instructions to prioritize non-GUI methods when possible.
  • [DATA_EXFILTRATION]: The skill uses network operations (curl, fetch) and local file access (output/reports/) to gather and store research data. These capabilities are aligned with the skill's primary purpose of report generation and no unauthorized data transfer patterns were found.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks. Ingestion points: Untrusted data enters the context from the web via search, fetch, and curl (SKILL.md). Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present. Capability inventory: The skill can generate files (pdf, doc, spreadsheet) and perform GUI actions (Cua). Sanitization: There are no instructions for sanitizing or escaping the gathered web content before it is processed.
  • [SAFE]: The skill's behavior is consistent with its stated purpose of research and reporting. It follows best practices by instructing the agent to cite sources and distinguish facts from inferences.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:31 PM
Security Audit — agent-trust-hub — clicky-research-report