research-external
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts using the
uv runcommand within a Bash shell to interact with MCP tools. - Evidence includes calls to
scripts/mcp/nia_docs.py,scripts/mcp/perplexity_search.py, andscripts/mcp/firecrawl_scrape.pyto process research queries. - [EXTERNAL_DOWNLOADS]: The skill is designed to fetch and process data from external sources.
- It interacts with established package registries including npm, PyPI, crates.io, and Go modules via the
nia-docstool. - It performs web scraping of arbitrary URLs found during the research process using the
firecrawltool. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its core function of processing untrusted web data.
- Ingestion points: Data enters the context via
firecrawl_scrape.py(scraped web pages),perplexity_search.py(web search results), andnia_docs.py(external package documentation). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious instructions embedded within the scraped research content during the synthesis phase.
- Capability inventory: The skill has
Bashaccess to execute scripts andWriteaccess to generate research documents and implementation handoffs. - Sanitization: The skill lacks explicit sanitization or filtering of the external content before interpolating it into the
handoffoutput, which is specifically intended to guide a implementation agent (plan-agent).
Audit Metadata