perplexity-search

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the open web via Perplexity search results and AI-synthesized research summaries. Maliciously crafted content on the web could attempt to override agent instructions or exfiltrate data.
  • Ingestion points: Results returned by scripts/mcp/perplexity_search.py as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the search results are documented.
  • Capability inventory: The skill has access to the Bash tool for command execution and the Read tool for file system access.
  • Sanitization: No specific filtering, validation, or sanitization of external content is mentioned.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute a local Python script (scripts/mcp/perplexity_search.py) using the uv runner. This is the primary intended mechanism for performing searches.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:14 PM
Security Audit — agent-trust-hub — perplexity-search