research-workspace-standard
Pass
Audited by Gen Agent Trust Hub on May 21, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill configuration allows the agent to access directories outside the current workspace via relative paths (e.g.,
../neighbor-project/). This capability exposes content from adjacent directories to the agent's context. - [PROMPT_INJECTION]: The skill contains instructions for the agent to ingest and follow rules from external workspace configuration files, creating a vulnerability to indirect prompt injection.
- Ingestion points: The agent is instructed to read
WORKSPACE.md,MEMORY.md, and scan files indocs/,research/, andtests/to establish session context and memory linkage. - Boundary markers: No explicit boundary markers or instructions to treat external file content as data rather than instructions are present.
- Capability inventory: The agent has the ability to read and write files across the local filesystem and navigate directory structures.
- Sanitization: The instructions do not define any sanitization or validation steps for the content retrieved from the codebase or configuration files.
Audit Metadata