sn-deep-research
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from external websites (via specialized search skills), which creates a surface for indirect prompt injection. However, the
review.mdandresearch.mdagent instructions explicitly include security protocols, commanding the agents to ignore any instructions found in retrieved data and to treat external content as untrusted evidence rather than operational directives. - [COMMAND_EXECUTION]: The skill executes local Python scripts (
validate_briefing.py,prepare_citations.py, etc.) and a Node.js runtime (sensenova-ppt-workbench.mjs) for internal orchestration tasks. These include document validation, citation formatting, and serving a local workbench UI on a dedicated port. - [EXTERNAL_DOWNLOADS]: The skill retrieves data from various well-known services such as GitHub, arXiv, and financial platforms through specialized search skills. These operations are essential to the primary research purpose of the skill.
- [CREDENTIALS_UNSAFE]: The skill documentation correctly identifies the need for API keys and tokens for various services and instructs the user to store them in a
.envfile at the repository root. This follows established security best practices for secret management by ensuring keys are loaded as environment variables rather than being hardcoded or passed through less secure channels.
Audit Metadata