research-agent
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands via
uv runto invoke Python scripts for research tasks (scripts/mcp/nia_docs.py,scripts/mcp/perplexity_search.py,scripts/mcp/firecrawl_scrape.py). These commands are used to interact with the agent's research tools. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data which introduces a surface for indirect prompt injection attacks.
- Ingestion points: Data is fetched from external sources via Nia (library documentation), Perplexity (web search/best practices), and Firecrawl (direct URL scraping) as described in
SKILL.mdunder "Step 2: Execute Research". - Boundary markers: The handoff template in
SKILL.md(Step 4) does not include explicit delimiters or "ignore instructions" warnings when interpolating findings from external sources. - Capability inventory: The skill executes local scripts via bash and writes findings to the file system as markdown files (
research-NN-<topic>.md). The generated handoff is intended for use by subsequent agents ("plan-agent" or "implement-agent"). - Sanitization: There is no evidence of sanitization or filtering of the external content before it is written to the handoff document.
Audit Metadata