deep-research
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's fundamental operation involves fetching and analyzing arbitrary content from the web via
WebFetchandWebSearch. This creates an attack surface where malicious websites could host content designed to manipulate the sub-agents. - Ingestion points: External data enters the agent's context through web searching and page fetching tools defined in
references/researcher.md. - Boundary markers: The instructions do not implement explicit delimiters or 'ignore instructions' warnings when processing external data.
- Capability inventory: The skill is equipped with
Bash(curl),Writefor file system operations, and theAgenttool for recursive orchestration. - Sanitization: No mechanisms for sanitizing or validating fetched content before analysis are described.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool for specific operations, including file downloads and document conversion usingcurl,pandoc, andmd-to-pdf. This grants the agent direct access to execute system utilities. - [EXTERNAL_DOWNLOADS]: As part of its research workflow, the skill is instructed to use
curlto download external files such as PDFs, datasets, and whitepapers. This necessitates interactions with remote servers whose reputation is not pre-verified.
Audit Metadata