explore
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to execute commands using
uv run researchkit. This refers to the local execution of theresearchkitproject, which is the primary purpose of the skill.- [DATA_INGESTION_SURFACE]: The skill processes data from the web through 'parallel sub-investigations' and 'web search' managed by the underlying tool. This involves ingesting untrusted external content into the agent's context. While this is an inherent surface for indirect prompt injection, it is fundamental to the skill's research function and no malicious patterns were identified in how the skill handles this data.- [SAFE]: The skill explicitly instructs against the use of API keys ('zero API keys', 'No API key is read at any step'), favoring local CLI subscription harnesses for privacy and cost management.
Audit Metadata