research

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local scripts and system commands to gather metadata and manage the research output.
  • It invokes the script hack/spec_metadata.sh to generate metadata such as researcher name and timestamps.
  • It uses git branch --show-current, git status, and gh repo view to retrieve repository-specific information for documentation headers.
  • It performs file system operations, including mkdir -p and writing researchers findings as markdown files into the thoughts/shared/research/ directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from the codebase, Linear tickets, and user-provided files, which creates a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to read codebase files, analyze Linear tickets (via linear-ticket-reader), and process user-mentioned documentation or JSON files (Step 1).
  • Boundary markers: The skill provides behavioral constraints (e.g., "You and all sub-agents are documentarians, not evaluators"), but it does not use explicit boundary delimiters or "ignore embedded instructions" warnings when processing the contents of external files.
  • Capability inventory: The agent has the ability to execute local scripts, perform network searches (via web-search-researcher), and write files to the local disk.
  • Sanitization: There is no evidence of sanitization or escaping of the ingested data before it is synthesized into the final research document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — research