deep-research

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to perform web research using reputable third-party tools (Firecrawl and Exa). No malicious commands, obfuscation, or unauthorized data access patterns were detected. It appropriately instructs the user to configure credentials in standard platform configuration files.
  • [PROMPT_INJECTION]: The skill processes untrusted data from external websites as part of its core research functionality. This is an inherent surface for indirect prompt injection where malicious instructions on a web page could attempt to influence the agent's output. In the context of a research tool, this is considered a low risk that does not escalate the overall verdict.
  • Ingestion points: External web content is ingested via firecrawl_scrape and crawling_exa tools (SKILL.md).
  • Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore instructions embedded in the retrieved web content.
  • Capability inventory: The agent uses MCP tools to search the web and read page content.
  • Sanitization: The instructions do not specify sanitization or filtering for the scraped text before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:58 PM
Security Audit — agent-trust-hub — deep-research