framework-docs-researcher
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
bundle showcommand to identify the installation paths of libraries on the local filesystem.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves and processes technical information from external, untrusted sources such as GitHub repositories and web search results. - Ingestion points: Documentation fetched via Context7, GitHub issues, pull requests, and general web search results.
- Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to ignore directives that might be present in the fetched content.
- Capability inventory: The agent can read local dependency manifests and source code, execute shell commands (
bundle show), and perform network operations for research. - Sanitization: No sanitization or validation of external content is described before it is integrated into the agent's context.
Audit Metadata