cross-reference-claim

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites through the WebFetch step in the research workflow.
  • Ingestion points: WebFetch is used in Step 2 to retrieve content from external URLs found during search queries.
  • Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore instructions found within the fetched content (e.g., in PDF metadata or webpage text).
  • Capability inventory: The skill lacks high-risk capabilities such as arbitrary command execution, file system writes, or persistence mechanisms, which significantly limits the potential impact of an injection attack.
  • Sanitization: There are no explicit instructions for sanitizing or validating the content of the retrieved documents before the agent extracts passages or results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:36 PM
Security Audit — agent-trust-hub — cross-reference-claim