deep-research

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains highly coercive and imperative instructions designed to bypass the agent's normal operational logic and force adherence to specific workflows through behavioral threats.
  • Evidence: Use of threatening language to enforce compliance: 'If you don't complete the steps... YOUR TASK WILL BE INVALIDATED. NO EXCEPTIONS.'
  • Evidence: Constraints on model selection for specific tool calls within the instruction body: 'MANDATORY: Always use model: "anthropic/claude-opus-4.6" for ALL Pal MCP tool calls. NEVER use any other model...'
  • [PROMPT_INJECTION]: (Indirect Prompt Injection Surface) The skill is designed to ingest and analyze potentially untrusted data from both the local codebase and external sources, creating a vector for instructions embedded in that data to influence the agent.
  • Ingestion points: Processes local codebase content via 'codebase_search' and external documentation/code via 'Sourcebot', 'Context7', and 'Perplexity'.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the researched data.
  • Capability inventory: Accesses architectural analysis tools ('mcp__zen__analyze', 'mcp__zen__debug', etc.) and broad search capabilities.
  • Sanitization: No evidence of sanitization, escaping, or filtering of the content retrieved from external or local sources.
  • [SAFE]: The skill references several external tools and command definitions through the '.claude/commands/' directory. These are documented as platform extensions for research and analysis.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — deep-research