web-researcher
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, focusing on teaching the agent how to perform effective web searches and evaluate data credibility. No malicious patterns or security risks were identified.
- [PROMPT_INJECTION]: The instructions do not contain any patterns attempting to override agent constraints, bypass safety filters, or extract system prompts. The language is standard for educational and procedural guidance.
- [DATA_EXFILTRATION]: There are no commands that access sensitive local files (e.g., .ssh, .aws, .env) or send user data to external servers. The use of web URLs in examples is limited to legitimate domains (Wikipedia, Reuters, Google Scholar).
- [REMOTE_CODE_EXECUTION]: The skill does not download, install, or execute any external scripts or packages. It relies entirely on the agent's built-in capabilities and provided instructions.
- [COMMAND_EXECUTION]: No shell commands, privilege escalation attempts (sudo), or persistence mechanisms were found in the instructions or examples.
- [SAFE]: The processing of external web data, which is the skill's primary purpose, is mitigated by instructions focusing on the CRAAP test for credibility evaluation and structured note-taking, rather than automated execution of retrieved content.
Audit Metadata