command-research-android

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill describes a research workflow that ingests content from external platforms (Play Store and Reddit), constituting an indirect prompt injection surface.
  • Ingestion points: Market and user research data collected from the Play Store and Reddit (SKILL.md).
  • Boundary markers: No delimiters or safety instructions are defined in the workflow contract to isolate untrusted external data from the agent's context.
  • Capability inventory: The skill coordinates sub-agents and associated skills to perform mobile development and research tasks (SKILL.md, agents/openai.yaml).
  • Sanitization: The provided configuration lacks logic for validating, escaping, or filtering instructions that might be embedded in the crawled research content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:17 PM
Security Audit — agent-trust-hub — command-research-android