investigate-without-getting-made

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines procedures for interacting with untrusted external data sources during investigations.\n
  • Ingestion points: The agent is instructed to visit and collect data from target websites, social media platforms, and online forums (SKILL.md, reference/persona-runbook.md).\n
  • Boundary markers: Robust boundary markers are present, including instructions to prefer third-party archives (e.g., read-deleted-pages) over live visits and strict warnings against authenticating to target-controlled infrastructure.\n
  • Capability inventory: The skill leverages capabilities for web browsing, image analysis, and metadata extraction.\n
  • Sanitization: Explicit steps for sanitizing output and stripping metadata from files are provided in the attribution-surface and persona runbooks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 12:20 PM
Security Audit — agent-trust-hub — investigate-without-getting-made