chatgpt-research
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to navigate to a well-known research service (chatgpt.com) using an in-app browser. It requires explicit user authorization or confirmation before starting research tasks.
- [PROMPT_INJECTION]: The instructions include defensive measures against indirect prompt injection. The skill mandates that the agent treat all external evidence, including webpages and research reports, as untrusted and forbids them from overriding the agent's primary operating instructions or authorization boundaries.
- [COMMAND_EXECUTION]: The skill implements a principle of least privilege by explicitly forbidding the creation, modification, or deletion of any local or repository files, limiting the agent to read-only research orchestration.
- [DATA_EXFILTRATION]: There are explicit prohibitions against transmitting sensitive data, including private repository content, personal files, credentials, or browsing history. The agent is directed to only submit non-sensitive research topics to the external service.
Audit Metadata