deep-research

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements its research functionality through documented tool calls and a structured workflow for data synthesis and reporting.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external web sources, which introduces an inherent surface for indirect prompt injection.
  • Ingestion points: Web content is ingested using the firecrawl_scrape and crawling_exa tools as described in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to handle potentially embedded commands in retrieved content.
  • Capability inventory: The skill utilizes web searching and scraping capabilities and can launch subagents via the Claude Code Task tool.
  • Sanitization: No explicit sanitization or validation of retrieved external content is specified before the data is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:19 AM
Security Audit — agent-trust-hub — deep-research