perplexity-search
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the open web via Perplexity search results and AI-synthesized research summaries. Maliciously crafted content on the web could attempt to override agent instructions or exfiltrate data.
- Ingestion points: Results returned by
scripts/mcp/perplexity_search.pyas described inSKILL.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the search results are documented.
- Capability inventory: The skill has access to the
Bashtool for command execution and theReadtool for file system access. - Sanitization: No specific filtering, validation, or sanitization of external content is mentioned.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute a local Python script (scripts/mcp/perplexity_search.py) using theuvrunner. This is the primary intended mechanism for performing searches.
Audit Metadata