investigate-without-getting-made
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines procedures for interacting with untrusted external data sources during investigations.\n
- Ingestion points: The agent is instructed to visit and collect data from target websites, social media platforms, and online forums (SKILL.md, reference/persona-runbook.md).\n
- Boundary markers: Robust boundary markers are present, including instructions to prefer third-party archives (e.g.,
read-deleted-pages) over live visits and strict warnings against authenticating to target-controlled infrastructure.\n - Capability inventory: The skill leverages capabilities for web browsing, image analysis, and metadata extraction.\n
- Sanitization: Explicit steps for sanitizing output and stripping metadata from files are provided in the attribution-surface and persona runbooks.
Audit Metadata