academic-deep-research

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a rigorous research framework with three mandatory user stop-points for clarifying scope, approving research plans, and reviewing the final report, ensuring human oversight at critical stages.
  • [SAFE]: Indirect Prompt Injection Surface Analysis: 1. Ingestion points: The skill ingests untrusted data from the web via web_search and web_fetch in Phase 3. 2. Boundary markers: Explicit markers or 'ignore' instructions are absent in the prompt interpolation. 3. Capability inventory: Includes web_search, web_fetch, sessions_spawn, and memory_search. 4. Sanitization: No explicit validation or filtering logic is present for fetched content. The risk is minimized by the mandated planning phase where the user approves specific themes and the search approach.
  • [COMMAND_EXECUTION]: Parallel research tracks are managed via the platform-native sessions_spawn tool, which is used according to its intended design to isolate independent investigation themes.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes web_fetch and web_search to retrieve external content for the purpose of analysis, which is consistent with its stated goal of performing deep research.
  • [DATA_EXFILTRATION]: There is no evidence of attempts to access sensitive system files, environment variables, or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 10:51 PM
Security Audit — agent-trust-hub — academic-deep-research