skills/kkenny0/loom/loom-research/Gen Agent Trust Hub

loom-research

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a comprehensive research pipeline for processing external materials. All operations, including content retrieval and file management, are conducted using built-in agent capabilities. No malicious code execution, credential harvesting, or unauthorized network operations were found.
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection as it is designed to process untrusted data from URLs, PDFs, and other files.
  • Ingestion points: Stage 1 processes content from external URLs, PDFs, and uploaded files (SKILL.md).
  • Boundary markers: The pipeline includes a strict 'quarantine' rule for Source Briefs to ensure they only reference their own specific source, which provides a degree of isolation (SKILL.md).
  • Capability inventory: The skill uses standard web tools to fetch content and performs file creation for research artifacts (SKILL.md).
  • Sanitization: No specific instructions for sanitizing or escaping ingested content are provided in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 03:06 AM
Security Audit — agent-trust-hub — loom-research