deep-research-skill

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured research protocol with a strong emphasis on evidence verification and source triangulation. It follows a decision-grade methodology that prioritizes auditability and hallucination resistance.
  • [PROMPT_INJECTION]: The skill includes explicit instructions for the agent to ignore any commands or instructions found within external web content (the 'Prompt Injection Firewall'). These safety directives are a best practice for agents that interact with the live web to prevent indirect prompt injection attacks.
  • [DATA_EXFILTRATION]: Research findings and state information are stored locally within a dedicated /RESEARCH/ directory. There is no evidence of hardcoded credentials or unauthorized data transmission to external domains.
  • [REMOTE_CODE_EXECUTION]: The skill orchestrates multiple research 'agents' and utilizes standard tools like Puppeteer and filesystem access through the platform's MCP (Model Context Protocol) interface. No suspicious external script downloads, remote binary execution, or obfuscated code patterns were detected.
  • [DYNAMIC_EXECUTION]: The use of a graph_state.json file is for maintaining the logical state of the research process (nodes, scores, and claims) rather than for executing dynamic code. This is a standard approach for complex, multi-step agentic workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 11:25 PM
Security Audit — agent-trust-hub — deep-research-skill