research-workspace-standard

Pass

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill configuration allows the agent to access directories outside the current workspace via relative paths (e.g., ../neighbor-project/). This capability exposes content from adjacent directories to the agent's context.
  • [PROMPT_INJECTION]: The skill contains instructions for the agent to ingest and follow rules from external workspace configuration files, creating a vulnerability to indirect prompt injection.
  • Ingestion points: The agent is instructed to read WORKSPACE.md, MEMORY.md, and scan files in docs/, research/, and tests/ to establish session context and memory linkage.
  • Boundary markers: No explicit boundary markers or instructions to treat external file content as data rather than instructions are present.
  • Capability inventory: The agent has the ability to read and write files across the local filesystem and navigate directory structures.
  • Sanitization: The instructions do not define any sanitization or validation steps for the content retrieved from the codebase or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 21, 2026, 08:11 AM
Security Audit — agent-trust-hub — research-workspace-standard