survey
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary function is to collect and organize information into Markdown reports. It defines a clean workflow for parallel data collection using sub-agents and specifies a local directory (
/reports/) for output. No evidence of credential harvesting, unauthorized command execution, or data exfiltration was detected. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core functionality of processing untrusted data from the web and social media.
- Ingestion points: External research data gathered from websites, academic papers, and social-media platforms (SKILL.md).
- Boundary markers: The skill explicitly mandates the use of code-block quotations (referenced via
writing-quotation) to separate source material from the agent's prose, and uses an Assertion-Evidence structure to ensure clarity of origin. - Capability inventory: The skill uses network search tools and writes generated reports to the
{CWD}/reports/directory (SKILL.md). - Sanitization: It includes instructions to sub-agents to avoid fabricated interpretations and requires the main agent to verify heading-content alignment and remove hallucinations.
Audit Metadata