framework-docs-researcher

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the bundle show command to identify the installation paths of libraries on the local filesystem.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves and processes technical information from external, untrusted sources such as GitHub repositories and web search results.
  • Ingestion points: Documentation fetched via Context7, GitHub issues, pull requests, and general web search results.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore directives that might be present in the fetched content.
  • Capability inventory: The agent can read local dependency manifests and source code, execute shell commands (bundle show), and perform network operations for research.
  • Sanitization: No sanitization or validation of external content is described before it is integrated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 06:26 PM
Security Audit — agent-trust-hub — framework-docs-researcher