cross-reference-claim
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites through the WebFetch step in the research workflow.
- Ingestion points: WebFetch is used in Step 2 to retrieve content from external URLs found during search queries.
- Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore instructions found within the fetched content (e.g., in PDF metadata or webpage text).
- Capability inventory: The skill lacks high-risk capabilities such as arbitrary command execution, file system writes, or persistence mechanisms, which significantly limits the potential impact of an injection attack.
- Sanitization: There are no explicit instructions for sanitizing or validating the content of the retrieved documents before the agent extracts passages or results.
Audit Metadata