skills/tonone-ai/tonone/cite-research/Gen Agent Trust Hub

cite-research

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's instructions and tool usage are consistent with its stated purpose of performing legal research. No malicious command execution, data exfiltration, or credential harvesting patterns were found.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests untrusted data from the internet. * Ingestion points: The WebSearch and WebFetch tools are used to gather regulatory guidance and case law (SKILL.md). * Boundary markers: There are no specific instructions or delimiters defined to separate untrusted web content from agent instructions. * Capability inventory: The skill has access to Bash, Write, Read, Glob, and Grep tools (SKILL.md frontmatter). * Sanitization: No explicit validation or filtering of external content is specified before the data is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:50 AM
Security Audit — agent-trust-hub — cite-research