research
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from the open web.
- Ingestion points: Web content retrieved via the
WebSearchtool from sources like ElixirForum, GitHub, and HexDocs. - Boundary markers: None specified. The skill does not define clear delimiters or instructions to the agent to ignore embedded commands within the fetched research material.
- Capability inventory: The skill can spawn subagents (
Agenttool), perform additional web searches, and write files to the local.claude/research/directory. - Sanitization: No evidence of sanitization, filtering, or validation of the external content before it is processed by the main agent or passed to subagents.
Audit Metadata