research-agent

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands via uv run to invoke Python scripts for research tasks (scripts/mcp/nia_docs.py, scripts/mcp/perplexity_search.py, scripts/mcp/firecrawl_scrape.py). These commands are used to interact with the agent's research tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data which introduces a surface for indirect prompt injection attacks.
  • Ingestion points: Data is fetched from external sources via Nia (library documentation), Perplexity (web search/best practices), and Firecrawl (direct URL scraping) as described in SKILL.md under "Step 2: Execute Research".
  • Boundary markers: The handoff template in SKILL.md (Step 4) does not include explicit delimiters or "ignore instructions" warnings when interpolating findings from external sources.
  • Capability inventory: The skill executes local scripts via bash and writes findings to the file system as markdown files (research-NN-<topic>.md). The generated handoff is intended for use by subsequent agents ("plan-agent" or "implement-agent").
  • Sanitization: There is no evidence of sanitization or filtering of the external content before it is written to the handoff document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — research-agent