research-team
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a rigorous multi-phase workflow (Context Discovery, Research Design, Collection, Analysis, Synthesis) grounded in academic methodologies like PRISMA 2020 and the Cochrane Handbook.
- [SAFE]: External resources and dependencies are limited to trusted organizations and well-known services, such as NIST, IPCC, the National Bureau of Economic Research (NBER), and official GitHub repositories of reputable entities (e.g., Anthropic, OpenSSF).
- [SAFE]: While the skill ingests untrusted data from web searches (Indirect Prompt Injection surface), it effectively mitigates risks through structured phases, calibrated confidence language, and the use of a separate quality-gate evaluator agent (Opus) to validate all results.
- [SAFE]: No obfuscation, hidden shell commands (e.g., in dynamic context injection), hardcoded credentials, or unauthorized network exfiltration patterns were found in the provided files.
- [SAFE]: The skill's use of specific vendor resources for its stated purpose of financial and academic research (e.g., Hedgeye, Universa) is consistent with its role and does not represent a security risk.
Audit Metadata