parallel-deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands via the Bash tool to run the parallel-cli research and polling functions. It interpolates variables such as $ARGUMENTS and $RUN_ID directly into command strings (e.g., parallel-cli research run "$ARGUMENTS"). If the agent fails to sanitize these inputs, it presents a risk for shell command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from two primary sources: the user-provided research topic and the external content retrieved from the internet during the research process. The skill lacks explicit boundary markers or instructions to the agent to ignore potentially malicious instructions embedded in the research results. The capabilities of this skill include executing shell commands and writing files to the local system, which increases the potential impact of an injection attack. Sanitization steps for external content are not visible in the provided skill definition.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes setup and upgrade instructions that involve downloading and installing packages from remote sources using package managers like pipx, npm, brew, and uv (e.g., pipx upgrade parallel-web-tools). While these resources appear to be associated with the intended vendor, they involve the acquisition and execution of remote code to set up the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:09 PM
Security Audit — agent-trust-hub — parallel-deep-research