search-first

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize command-line tools like rg (ripgrep) for scanning local repositories and interacts with package managers such as npm and pip to integrate third-party dependencies.
  • [EXTERNAL_DOWNLOADS]: The workflow involves searching and potentially downloading software from public registries including npm, PyPI, and GitHub, referencing several common and reputable libraries as examples.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by directing the agent to ingest and act upon untrusted content from external search results.
  • Ingestion points: Metadata and documentation from npm, PyPI, GitHub, and general web search results.
  • Boundary markers: Not present.
  • Capability inventory: Execution of shell commands, file system modification, and network access.
  • Sanitization: Not present.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — search-first