agent-research

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill uses the Nimble Agent API (app.nimbleway.com), which is the official platform for the skill's author. It does not attempt to exfiltrate data to unauthorized third-party domains.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs users to manage the NIMBLE_API_KEY via a .env file and includes explicit instructions never to print or echo the key in the agent's output.
  • [DATA_EXPOSURE]: The skill mentions that researched web content is untrusted data and explicitly warns against following instructions found within that content (Indirect Prompt Injection mitigation).
  • [COMMAND_EXECUTION]: No shell command execution or risky subprocess spawning is present in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 08:50 PM
Security Audit — agent-trust-hub — agent-research