research-tech
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of content from untrusted external sources. While this introduces a surface for indirect prompt injection, it is an inherent part of the research function. Ingestion points:
references/agent-prompts.mddefines agents usingWebFetchandmcp__jina__read_url. Boundary markers: Current templates do not include specific delimiters or explicit instructions to disregard instructions within the fetched data. Capability inventory: The skill is scoped to searching, fetching, and synthesizing web-based information. Sanitization: The retrieved content is processed directly to generate research summaries. - [DATA_EXFILTRATION]: The skill interacts with well-known developer platforms like GitHub and StackOverflow to retrieve technical information. Evidence: The agent prompts in
references/agent-prompts.mddefine workflows targeting these services for research purposes. - [SAFE]: The skill provides best-practice guidelines in
references/fake-stars.mdfor vetting the credibility of GitHub metrics, preventing the agent from being misled by manipulated popularity signals.
Audit Metadata