sn-deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from external websites (via specialized search skills), which creates a surface for indirect prompt injection. However, the review.md and research.md agent instructions explicitly include security protocols, commanding the agents to ignore any instructions found in retrieved data and to treat external content as untrusted evidence rather than operational directives.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (validate_briefing.py, prepare_citations.py, etc.) and a Node.js runtime (sensenova-ppt-workbench.mjs) for internal orchestration tasks. These include document validation, citation formatting, and serving a local workbench UI on a dedicated port.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from various well-known services such as GitHub, arXiv, and financial platforms through specialized search skills. These operations are essential to the primary research purpose of the skill.
  • [CREDENTIALS_UNSAFE]: The skill documentation correctly identifies the need for API keys and tokens for various services and instructs the user to store them in a .env file at the repository root. This follows established security best practices for secret management by ensuring keys are loaded as environment variables rather than being hardcoded or passed through less secure channels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-deep-research