deep-dive
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading codebase files during its research phase, creating a potential surface for indirect instructions.\n
- Ingestion points: The 'deep research' operation involves reading project files, architecture, and dependency information as described in SKILL.md.\n
- Boundary markers: The instructions do not specify explicit delimiters or 'ignore' directives to prevent the agent from obeying instructions that might be embedded in the files it analyzes.\n
- Capability inventory: The skill possesses capabilities for reading project files and writing findings to the local 'deep-dive/' directory.\n
- Sanitization: There is no mention of content sanitization or validation of codebase data before it is processed into research or innovation documentation.
Audit Metadata