academic-deep-research
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a rigorous research framework with three mandatory user stop-points for clarifying scope, approving research plans, and reviewing the final report, ensuring human oversight at critical stages.
- [SAFE]: Indirect Prompt Injection Surface Analysis: 1. Ingestion points: The skill ingests untrusted data from the web via
web_searchandweb_fetchin Phase 3. 2. Boundary markers: Explicit markers or 'ignore' instructions are absent in the prompt interpolation. 3. Capability inventory: Includesweb_search,web_fetch,sessions_spawn, andmemory_search. 4. Sanitization: No explicit validation or filtering logic is present for fetched content. The risk is minimized by the mandated planning phase where the user approves specific themes and the search approach. - [COMMAND_EXECUTION]: Parallel research tracks are managed via the platform-native
sessions_spawntool, which is used according to its intended design to isolate independent investigation themes. - [EXTERNAL_DOWNLOADS]: The skill utilizes
web_fetchandweb_searchto retrieve external content for the purpose of analysis, which is consistent with its stated goal of performing deep research. - [DATA_EXFILTRATION]: There is no evidence of attempts to access sensitive system files, environment variables, or hardcoded credentials.
Audit Metadata