web-research

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes arbitrary content from the web to be summarized by the agent, creating a surface for indirect prompt injection attacks.
  • Ingestion points: External content is ingested via scripts/research.py which coordinates fetching through the defuddle CLI or the tavily_extract.py script.
  • Boundary markers: Fetched content is saved to markdown files. In tavily_extract.py, content is wrapped in a markdown code block to attempt to delimit it from the rest of the prompt.
  • Capability inventory: The skill has the ability to write multiple files to the local file system (research-output directory) and execute local scripts.
  • Sanitization: The skill performs minimal sanitization by wrapping raw HTML/text into markdown blocks, but does not filter for embedded instructions that might influence the agent's summary.
  • [COMMAND_EXECUTION]: The skill executes external commands and local scripts using subprocess.run.
  • Evidence: scripts/research.py invokes the defuddle CLI tool (if found in the system PATH) and its own helper scripts (tavily_search.py, tavily_extract.py) to process web data. It correctly uses list-based arguments rather than shell strings, which mitigates standard shell injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to external services to retrieve data.
  • Evidence: The scripts tavily_search.py and tavily_extract.py communicate with api.tavily.com using urllib.request. This behavior is transparently documented in the skill's compatibility metadata and documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:21 PM
Security Audit — agent-trust-hub — web-research