brave-search
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external websites via search results, which could potentially contain adversarial instructions designed to influence the agent's behavior. This is an inherent risk for any web search capability.
- Ingestion points: Search result descriptions and snippets in
brave.pyandsrc/brave_search/cli.py. - Boundary markers: No explicit delimiters are applied to the external search content before it is presented to the agent.
- Capability inventory: Network access restricted to the well-known Brave Search API; no file-write or subprocess execution capabilities are present in the skill's code.
- Sanitization: Content is retrieved and displayed without specific sanitization against prompt injection patterns.
Audit Metadata