research
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The research skill possesses an attack surface for indirect prompt injection due to its core function of retrieving and analyzing content from the internet.\n
- Ingestion points: The skill uses WebSearch and WebFetch tools in SKILL.md to ingest untrusted data from external websites.\n
- Boundary markers: The instructions in SKILL.md explicitly command sub-agents to follow references/methodology.md and state they must not implement code or edit files, providing a protective behavioral boundary.\n
- Capability inventory: The skill and its sub-agents have access to potentially impactful tools such as Bash, Write, Agent, and Skill.\n
- Sanitization: There is no explicit evidence of sanitization or filtering logic applied to the data fetched from the web before it is processed by the AI models.
Audit Metadata