youtube-brief
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
WebSearchtool and a research subagent in Steps 4 and 5 to gather external information from the internet, including articles and community discussions. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted data from external sources and has the capability to write to the file system.
- Ingestion points: Step 4 and Step 5 utilize
WebSearchand theTasktool (research subagent) to ingest external data. - Boundary markers: Absent; there are no specific instructions to the agent to treat external content as untrusted or to ignore instructions embedded within it.
- Capability inventory: Step 6 directs the agent to save the generated brief to a markdown file in the local directory.
- Sanitization: Absent; the skill does not define any validation or filtering for the data retrieved from external research.
- [NO_CODE]: This skill consists entirely of instructional markdown and reference files. It does not contain any executable scripts or binaries.
Audit Metadata