research-report
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains instructional guidelines for formatting, structure, and tone of research reports. It does not include any executable code, remote dependencies, or sensitive file access.
- [COMMAND_EXECUTION]: The instructions suggest generating images or charts using standard tools like
python3orbash. This is a routine use of agent capabilities for data visualization and does not constitute a security risk in this context. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing data from external research sources (tool outputs). While this creates an attack surface for indirect prompt injection, the skill's instructions emphasize factual verification, citation of authoritative sources, and neutral reporting, which are effective mitigation practices.
- Ingestion points: External research data retrieved via tool calls (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: File writing, command execution (Python/Bash for charts), and file display (show).
- Sanitization: Instructions require validating facts against primary sources and prohibiting fabricated URLs.
Audit Metadata