auto-research

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the ingestion of untrusted data from external sources.
  • Ingestion points: The agent retrieves content from the public web and ChatGPT responses as described in SKILL.md.
  • Boundary markers: The skill instructs the agent to present findings to the user for final approval, but it lacks instructions for using delimiters or 'ignore' commands when the agent initially processes the raw untrusted data from the web.
  • Capability inventory: The skill utilizes playwright for browser automation and is intended to eventually write and implement code based on findings.
  • Sanitization: While the skill requires redaction of sensitive local data before sending it externally, it does not specify sanitization or validation of the incoming data retrieved from the web.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:02 PM
Security Audit — agent-trust-hub — auto-research