research-dojo

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not contain any attempts to bypass safety filters, override core agent behavior, or extract system prompts. The 'Research Adversary' persona is used strictly for critical thinking and does not encourage rule-breaking.
  • [DATA_EXFILTRATION]: No patterns for accessing sensitive files (e.g., credentials, SSH keys) or exfiltrating data to external servers were found. The skill operates within the user-defined workspace and uses standard web search tools for grounding.
  • [REMOTE_CODE_EXECUTION]: The skill does not attempt to download or execute remote scripts. References to installation commands (npx) in the documentation are user-facing setup instructions and are not executed by the agent at runtime.
  • [COMMAND_EXECUTION]: The skill does not perform any arbitrary command execution or subprocess spawning. Its activities are limited to logical analysis, structured text generation, and reading/writing research files in specific directories.
  • [EXTERNAL_DOWNLOADS]: The skill references other repositories for companion tools ('truedraft', 'book-writer') owned by the same author (kshanxs). These are documented as part of a modular workflow and do not represent suspicious external dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the web (via searches in Step 4) and user-supplied topics. While this presents a standard attack surface for indirect injection, the skill's highly structured 7-step pipeline and lack of executable capabilities (like eval/exec) mitigate the risk of these inputs causing harmful actions beyond text generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 01:17 AM
Security Audit — agent-trust-hub — research-dojo