research-external

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts using the uv run command within a Bash shell to interact with MCP tools.
  • Evidence includes calls to scripts/mcp/nia_docs.py, scripts/mcp/perplexity_search.py, and scripts/mcp/firecrawl_scrape.py to process research queries.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to fetch and process data from external sources.
  • It interacts with established package registries including npm, PyPI, crates.io, and Go modules via the nia-docs tool.
  • It performs web scraping of arbitrary URLs found during the research process using the firecrawl tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its core function of processing untrusted web data.
  • Ingestion points: Data enters the context via firecrawl_scrape.py (scraped web pages), perplexity_search.py (web search results), and nia_docs.py (external package documentation).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the scraped research content during the synthesis phase.
  • Capability inventory: The skill has Bash access to execute scripts and Write access to generate research documents and implementation handoffs.
  • Sanitization: The skill lacks explicit sanitization or filtering of the external content before interpolating it into the handoff output, which is specifically intended to guide a implementation agent (plan-agent).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — research-external