research

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external primary sources which represents a potential attack surface.
  • Ingestion points: The agent is instructed to read official documentation, source code, specifications, and first-party APIs.
  • Boundary markers: Absent. The instructions do not specify any delimiters or warnings to ignore embedded instructions within the researched materials.
  • Capability inventory: The skill performs file system write operations by saving findings as Markdown files in the repository.
  • Sanitization: Absent. There are no instructions to sanitize, escape, or validate the content retrieved from external sources before writing it to the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:01 PM
Security Audit — agent-trust-hub — research