deep-research-with-instructions

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of ingesting and summarizing untrusted data from external websites.
  • Ingestion points: External data enters the agent's context through tools such as mcp__exa__web_search_exa, mcp__exa__crawling_exa, WebFetch, and mcp__plugin_context7_context7__query-docs (as documented in SOURCES.md).
  • Boundary markers: There are no specific boundary markers or instructions to ignore potential commands within the fetched content implemented in the research prompts.
  • Capability inventory: The skill possesses capabilities including writing to local files (creating and updating state and findings in the .plans/ directory and modifying .gitignore), prompting the user via AskUserQuestion, and delegating tasks to general-purpose sub-agents (referenced in SKILL.md).
  • Sanitization: The instructions do not include steps to sanitize, escape, or validate external content before it is incorporated into findings or passed to sub-agents for summarization.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 07:36 AM
Security Audit — agent-trust-hub — deep-research-with-instructions