industry-research-advisor

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze data from external websites, creating a surface for indirect prompt injection.\n- Ingestion points: External sources such as industry white papers, financial reports, and patent data fetched using web_fetch and search tools as specified in SKILL.md.\n- Boundary markers: The instructions lack explicit delimiters or warnings to treat fetched content as untrusted data.\n- Capability inventory: No high-risk capabilities like local file writing, credential access, or shell command execution were identified in the skill scripts or instructions.\n- Sanitization: There are no instructions provided to validate or sanitize the data retrieved from external sources before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 04:17 AM
Security Audit — agent-trust-hub — industry-research-advisor