deep-research
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands to orchestrate its research pipeline and run bundled Python validation scripts. It also includes instructions for the agent to publish reports using a project-specific command (
pnpm run sync:research) targeting the author's domain (lovstudio.ai), which is a documented vendor-specific functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes large volumes of untrusted data from the web, which constitutes an indirect prompt injection surface.
- Ingestion points: External data is ingested via search tools like
search-cliandWebSearchduring the retrieval phase. - Boundary markers: The skill methodology (
methodology.md) explicitly defines a 'Source trust boundary', instructing the agent to treat web content strictly as data and not as instructions. - Capability inventory: The skill possesses the ability to write files to the disk and execute shell commands for validation and publishing.
- Sanitization: The skill employs multiple validation layers, including automated lexical overlap checking in
verify_claim_support.pyand DOI/URL verification inverify_citations.pyto ensure information integrity. - [EXTERNAL_DOWNLOADS]: The documentation recommends installing
search-clifrom the199-biotechnologiesGitHub repository to enhance search capabilities. This is an optional external tool utilized for its primary research purpose.
Audit Metadata