search-synthesis-expert
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to browse the internet and ingest content from arbitrary websites to perform synthesis and review. This functionality creates a potential surface for indirect prompt injection, where instructions embedded in external web content could attempt to influence the agent's final report or behavior. This is an inherent risk for any agent with web-browsing capabilities.
- Ingestion points: Page content extraction in Phase 2 (SKILL.md).
- Boundary markers: The skill does not define specific delimiters or 'ignore' instructions for the ingested content.
- Capability inventory: Uses Playwright for web interaction and sequential reasoning for synthesis (SKILL.md).
- Sanitization: No specific sanitization or validation of the ingested external content is mentioned.
Audit Metadata