research
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes the contents of
docs/brainstorms/<workflow_id>.mdto derive research queries and synthesize output. \n - Ingestion points: Reads the full content of the brainstorm document at
docs/brainstorms/<workflow_id>.mdin Step 2.\n - Boundary markers: Absent; there are no instructions to the agent to treat the document content as untrusted data or to ignore embedded instructions.\n
- Capability inventory: Includes file system write access to
docs/research/, codebase search capabilities, and the execution of thesubstrate-readtool.\n - Sanitization: Absent; the skill is instructed to adopt the vocabulary and terms found within the brainstorm document for its queries and reports.
Audit Metadata