deep-read
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its document processing nature. \n
- Ingestion points: External data is ingested in
Workflows/01-capture.mdviamcp__web-reader__webReader(URLs) and theReadtool (PDFs and local files). \n - Boundary markers: Absent. In
Workflows/02-read.md, untrusted content is passed directly to background agents using the template{素材全文或关键段落}without delimiters or instructions to ignore embedded instructions. \n - Capability inventory: The skill uses
Read,Write, andWebSearchtools, allowing for file system interaction and network access based on processed content. \n - Sanitization: No escaping or filtering of external content is specified before interpolation into prompts.
Audit Metadata