think-research-framework

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local JavaScript validator, scripts/check-proposed-entry.mjs, to ensure generated registry entries conform to the expected schema.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of untrusted data.
  • Ingestion points: Untrusted data enters the agent context through user-supplied framework names or briefs, as well as via web search results processed by the think-research-framework subagent.
  • Boundary markers: There are no explicit instructions or delimiters defined in the SKILL.md to instruct the subagent to ignore instructions embedded within the researched content.
  • Capability inventory: The skill has the capability to write files to the staging directory (frameworks/_proposed/<slug>/dossier.md) and execute a local validation script (scripts/check-proposed-entry.mjs).
  • Sanitization: The skill employs a schema validator (check-proposed-entry.mjs) for the registry entry artifact, which provides a layer of validation for structured output, but does not necessarily prevent prompt injection within the research dossier prose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:39 PM
Security Audit — agent-trust-hub — think-research-framework