industry-research-advisor
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze data from external websites, creating a surface for indirect prompt injection.\n- Ingestion points: External sources such as industry white papers, financial reports, and patent data fetched using
web_fetchand search tools as specified in SKILL.md.\n- Boundary markers: The instructions lack explicit delimiters or warnings to treat fetched content as untrusted data.\n- Capability inventory: No high-risk capabilities like local file writing, credential access, or shell command execution were identified in the skill scripts or instructions.\n- Sanitization: There are no instructions provided to validate or sanitize the data retrieved from external sources before processing.
Audit Metadata