deep-dive
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external code and documentation which may contain untrusted content.
- Ingestion points: The
deep researchoperation involves reading project files, code structure, architecture, and dependencies. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore or isolate instructions that might be embedded within the external files being analyzed.
- Capability inventory: The skill utilizes file read capabilities and file write capabilities (targeting the
deep-dive/directory). No network operations or arbitrary command execution patterns are defined. - Sanitization: There is no explicit requirement for the agent to sanitize or escape content read from external files before summarizing findings or recording them to research documents.
Audit Metadata