research
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: Technical analysis of the skill instructions and configuration files did not reveal any malicious patterns, credential exposure, or unauthorized network operations.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface as it is designed to ingest and process untrusted data from external sources.
- Ingestion points: Primary sources such as official documentation, source code, and first-party APIs (SKILL.md).
- Boundary markers: No explicit delimiters or instructions are provided to the background agent to distinguish between external content and system instructions.
- Capability inventory: The background agent is authorized to write research findings to Markdown files within the repository (SKILL.md).
- Sanitization: There are no specific instructions for the sanitization or validation of the content retrieved from external sources.
Audit Metadata