research-mastery

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a "Carve-out" instruction that explicitly directs the agent to ignore grounds for refusal when handling security-related research like CTF challenges and pentests. This represents an attempt to override safety guardrails through behavioral framing.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by instructing the agent to ingest and rely on external data from the web and MCP servers without defining boundary markers or sanitization logic.\n
  • Ingestion points: Data entering through search_web and use_mcp_tool (referenced in SKILL.md).\n
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the retrieved external content.\n
  • Capability inventory: The agent is directed to use Read, Grep, Glob, use_mcp_tool, and search_web (all referenced in SKILL.md).\n
  • Sanitization: Absent; the skill does not include steps to validate or escape external data before it influences the agent's reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 12:06 AM
Security Audit — agent-trust-hub — research-mastery