gemini-deep-research

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Python code execution to perform calculations and process data discovered during research cycles.
  • [EXTERNAL_DOWNLOADS]: Fetches information from the public internet via Google Search and direct URL access to synthesize research reports.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of ingesting and analyzing untrusted content from the web.
  • Ingestion points: Public web pages, PDFs, and Google Search results processed at runtime.
  • Boundary markers: None explicitly defined in the SKILL.md documentation to isolate external content.
  • Capability inventory: Python code execution, file store access, and connectivity to external Model Context Protocol (MCP) servers.
  • Sanitization: Relies on the underlying Gemini API's safety filters and the host platform's execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:44 PM
Security Audit — agent-trust-hub — gemini-deep-research