skills/samber/cc-skills/deep-research/Gen Agent Trust Hub

deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's fundamental operation involves fetching and analyzing arbitrary content from the web via WebFetch and WebSearch. This creates an attack surface where malicious websites could host content designed to manipulate the sub-agents.
  • Ingestion points: External data enters the agent's context through web searching and page fetching tools defined in references/researcher.md.
  • Boundary markers: The instructions do not implement explicit delimiters or 'ignore instructions' warnings when processing external data.
  • Capability inventory: The skill is equipped with Bash(curl), Write for file system operations, and the Agent tool for recursive orchestration.
  • Sanitization: No mechanisms for sanitizing or validating fetched content before analysis are described.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool for specific operations, including file downloads and document conversion using curl, pandoc, and md-to-pdf. This grants the agent direct access to execute system utilities.
  • [EXTERNAL_DOWNLOADS]: As part of its research workflow, the skill is instructed to use curl to download external files such as PDFs, datasets, and whitepapers. This necessitates interactions with remote servers whose reputation is not pre-verified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:00 PM
Security Audit — agent-trust-hub — deep-research