discovery-interview

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources during its research phase.
  • Ingestion points: The agent is instructed to use WebSearch and WebFetch tools to gather information from the internet when it detects knowledge gaps or uncertainty in user responses.
  • Boundary markers: The skill body lacks explicit instructions or delimiters to isolate fetched web content from the agent's internal logic, creating a surface for embedded instructions in web content to influence the agent.
  • Capability inventory: The skill has the capability to write files to the local filesystem (generating specifications in thoughts/shared/specs/) and the ability to spawn sub-agents (oracle agents).
  • Sanitization: While the skill asks the agent to summarize findings, it does not define specific validation, filtering, or safety protocols for the external content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:56 PM
Security Audit — agent-trust-hub — discovery-interview