research-tasks

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of untrusted external data. \n
  • Ingestion points: The skill uses web_search and browser tools to fetch content from the open web (SKILL.md). \n
  • Boundary markers: There are no explicit instructions or delimiters defined to separate untrusted web content from the agent's core instructions. \n
  • Capability inventory: The skill possesses the ability to write findings to the local workspace within the notes/ directory (SKILL.md). \n
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content retrieved from external sources before it is processed or saved.
  • [NO_CODE]: The skill consists entirely of markdown instructions and does not include any executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 12:02 AM
Security Audit — agent-trust-hub — research-tasks