research-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources and stored knowledge without utilizing boundary markers or sanitization, creating a surface for potential injection attacks.
- Ingestion points: Data retrieved through the
WebSearchtool and existing content fetched viaqdrant-findas described in SKILL.md. - Boundary markers: The instructions do not define delimiters or specific markers to isolate untrusted external content from the agent's internal reasoning.
- Capability inventory: The skill utilizes
qdrant-storefor writing findings,qdrant-findfor reading stored data, andWebSearchfor external information retrieval. - Sanitization: There are no instructions provided for validating, filtering, or sanitizing the content retrieved from external searches before it is processed or stored.
Audit Metadata