prospect-research-compiler

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill aggregates intelligence from external, untrusted sources such as news, social media, and third-party websites. This creates an attack surface for indirect prompt injection, where malicious instructions embedded in these sources could attempt to subvert the agent's behavior.
  • Ingestion points: Intelligence gathered from news, social media, and websites as described in SKILL.md.
  • Boundary markers: Absent. There are no instructions for the agent to distinguish between data and instructions when processing external content.
  • Capability inventory: The skill uses the agent's default tools to read and aggregate data. No specific execution tools are defined in this skill.
  • Sanitization: Absent. There is no mechanism described for filtering or sanitizing the content fetched from the web.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — prospect-research-compiler