researchers-gov
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites via
WebFetchandWebSearchbased on user-provided search terms. While the skill instructions focus on extraction and citation, there are no explicit boundary markers or instructions for the agent to disregard potential instructions embedded in the fetched content. Since the agent also possessesWriteandEditcapabilities, this creates a theoretical surface where malicious data from a web page could attempt to influence the agent's file system operations. - [EXTERNAL_DOWNLOADS]: The skill is configured to interact with well-known government domains such as justice.gov, fbi.gov, and sec.gov to retrieve official press releases and reports. These are legitimate targets for the skill's stated purpose.
Audit Metadata