think-research-framework
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local JavaScript validator,
scripts/check-proposed-entry.mjs, to ensure generated registry entries conform to the expected schema. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of untrusted data.
- Ingestion points: Untrusted data enters the agent context through user-supplied framework names or briefs, as well as via web search results processed by the
think-research-frameworksubagent. - Boundary markers: There are no explicit instructions or delimiters defined in the SKILL.md to instruct the subagent to ignore instructions embedded within the researched content.
- Capability inventory: The skill has the capability to write files to the staging directory (
frameworks/_proposed/<slug>/dossier.md) and execute a local validation script (scripts/check-proposed-entry.mjs). - Sanitization: The skill employs a schema validator (
check-proposed-entry.mjs) for the registry entry artifact, which provides a layer of validation for structured output, but does not necessarily prevent prompt injection within the research dossier prose.
Audit Metadata