deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown files providing guidelines for research and reporting. No executable code, remote script downloads, persistence mechanisms, or obfuscated patterns were found across the provided files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web sources and local files during research tasks, which represents an inherent surface for indirect prompt injection. 1. Ingestion points: Web search results, browser content, and local code references (defined in SKILL.md and search-strategies.md). 2. Boundary markers: The skill instructs the agent to use the host's citation format and requires citations to be placed near the specific claims they support. 3. Capability inventory: The skill instructions imply capabilities for web searching, browser interaction, and reading local file implementations. 4. Sanitization: Instructions require the agent to paraphrase sources and reserve short, marked quotes only for exact wording that matters, which serves as a prompt-level sanitization method to prevent direct passthrough of malicious instructions. The ingestion of untrusted data is a core function of the research skill and is handled with appropriate instructional guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:59 PM
Security Audit — agent-trust-hub — deep-research