cite-sources

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process external content and user arguments to generate citations, which constitutes an indirect prompt injection surface. This is the primary function of the skill.
  • Ingestion points: The $ARGUMENTS variable and content retrieved via external tools (SKILL.md).
  • Boundary markers: None present; the instructions do not specify delimiters for the external content.
  • Capability inventory: The skill utilizes the WebFetch tool to resolve and validate URLs (SKILL.md).
  • Sanitization: No sanitization or validation of the input content is performed prior to processing.
  • [EXTERNAL_DOWNLOADS]: Installation instructions provided in the README reference fetching resources from the author's GitHub repository.
  • Evidence: npx skills add https://github.com/synapseradio/ai-skills and a direct download link for a .skill file from the synapseradio/ai-skills repository (README.md). These are vendor-owned resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:24 PM
Security Audit — agent-trust-hub — cite-sources