search-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to search, extract, and synthesize information from the web, which constitutes an ingestion point for untrusted data. This makes the agent potentially vulnerable to malicious instructions embedded in third-party websites.
- Ingestion points: The 'WebFetch Deep Dive' instructions specifically direct the agent to 'Extract full content from promising results' and 'Parse structured data from pages'.
- Boundary markers: The instructions do not define clear delimiters or specify that the agent should ignore instructions found within the content it fetches.
- Capability inventory: The skill is designed to operate within an environment where web search and content retrieval tools are available, which are the main capabilities leveraged by the ingested data.
- Sanitization: There are no explicit sanitization or filtering steps defined to strip potential instructions from external web content before synthesis.
Audit Metadata