research
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local scripts and system commands to gather metadata and manage the research output.
- It invokes the script
hack/spec_metadata.shto generate metadata such as researcher name and timestamps. - It uses
git branch --show-current,git status, andgh repo viewto retrieve repository-specific information for documentation headers. - It performs file system operations, including
mkdir -pand writing researchers findings as markdown files into thethoughts/shared/research/directory. - [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from the codebase, Linear tickets, and user-provided files, which creates a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to read codebase files, analyze Linear tickets (via
linear-ticket-reader), and process user-mentioned documentation or JSON files (Step 1). - Boundary markers: The skill provides behavioral constraints (e.g., "You and all sub-agents are documentarians, not evaluators"), but it does not use explicit boundary delimiters or "ignore embedded instructions" warnings when processing the contents of external files.
- Capability inventory: The agent has the ability to execute local scripts, perform network searches (via
web-search-researcher), and write files to the local disk. - Sanitization: There is no evidence of sanitization or escaping of the ingested data before it is synthesized into the final research document.
Audit Metadata