research-methodology
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a lifecycle for ingesting and acting upon untrusted data from external sources including support forums, git histories, and public web content. 1. Ingestion points: Systematic discovery described in references/research-lifecycle.md and references/journalistic-research.md involves fetching data from arbitrary URLs and community-driven platforms. 2. Boundary markers: The framework relies on analytical evaluation frameworks (CRAAP test) rather than technical prompt delimiters to manage untrusted content. 3. Capability inventory: references/technical-verification.md explicitly instructs the agent to use shell commands, Python scripts, curl, and system monitoring tools to verify external claims. 4. Sanitization: No explicit technical sanitization or escaping instructions are provided for the interpolation of external data into shell commands.
- [COMMAND_EXECUTION]: The technical-verification.md reference guide provides instructions for the agent to execute system commands such as curl, nvidia-smi, ps, du, and htop, as well as running custom Python scripts. These capabilities are intended for verifying research evidence but facilitate a path for command execution influenced by external source material.
Audit Metadata