skills/jcosta33/skills/sus-research/Gen Agent Trust Hub

sus-research

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages the creation and cleanup of research artifacts in the ~/.agents/artifacts/ directory. It specifically instructs the agent to delete files and verify their removal during the closing phase of a task in SKILL.md.- [INDIRECT_PROMPT_INJECTION]: The skill is intended to process external and potentially untrusted information from sources like product documentation, user reviews, and third-party reports as defined in references/market-method.md. This ingestion surface could be exploited by malicious content within those sources to influence the agent's conclusions.
  • Ingestion points: External API documentation, benchmarks, market reports, and customer reviews.
  • Boundary markers: The skill instructs the agent to mark unsupported claims as [unconfirmed] and match source competence to each claim.
  • Capability inventory: The agent is instructed to perform file system operations (write and delete) within the ~/.agents/artifacts/ path.
  • Sanitization: The methodology requires structured confidence assessment and triangulation of evidence, which serves as a logical filter for external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 05:04 PM
Security Audit — agent-trust-hub — sus-research