research-brief

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted web content from the Tavily search tool to generate research briefs, creating a surface for indirect prompt injection. Malicious instructions on target websites could potentially manipulate the content of the generated brief published to Notion.\n
  • Ingestion points: External web content retrieved via the Tavily MCP integration (SKILL.md).\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore commands within the gathered research data during prompt construction.\n
  • Capability inventory: Writing and publishing content to Notion via the Notion MCP (SKILL.md).\n
  • Sanitization: No sanitization or validation of the retrieved web content is performed before interpolation into the research prompt.\n- [COMMAND_EXECUTION]: The setup workflow executes a curl command to register the automation with the platform's backend (SKILL.md). This operation is documented as safe as it uses platform-provided environment variables ($OPENHANDS_HOST, $OPENHANDS_AUTOMATION_API_KEY) for a vendor-specific API endpoint.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 11:05 AM
Security Audit — agent-trust-hub — research-brief