skills/onmax/skills/evidence-research/Gen Agent Trust Hub

evidence-research

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform filesystem operations, including resolving absolute project roots, creating research directories, and writing artifact files (brief.md, reports/, synthesis.md) to the OS temporary directory.
  • [DATA_EXFILTRATION]: To fulfill its purpose, the skill accesses sensitive internal project data such as repository history, pull requests, issues, and local documentation. While this is the primary intent of the skill, it represents a significant data access surface.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external content (e.g., technical blogs, public documentation, and community writing) and project-local data during the evidence-gathering phase.
  • Ingestion points: External ecosystem documentation and internal project artifacts (PRs, issues, history) as defined in SKILL.md and RESEARCH-RIGOR.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external research content as untrusted data rather than instructions.
  • Capability inventory: The skill requires filesystem read/write access (project root and temporary directories) and the ability to spawn subagents or execute local research passes.
  • Sanitization: The instructions do not specify any validation or sanitization steps for data gathered from external sources before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 05:13 AM
Security Audit — agent-trust-hub — evidence-research