auto-research
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill features an inherent surface for indirect prompt injection because its core function involves ingesting and analyzing data from untrusted external sources.
- Ingestion points: The workflow relies on
intelli_research,web_fetch, and file reading tools to acquire data from the web and local files. - Boundary markers: The instructions do not mandate the use of delimiters to isolate retrieved content from the agent's logic, which is common in research-oriented skills.
- Capability inventory: Capabilities include web searching, URL fetching, and reading local files or cloned repositories.
- Sanitization: No specific filtering or escaping of retrieved content is requested in the research templates.
- [SAFE]: The skill uses established tools for its stated purpose, lacks obfuscation, and does not contain hardcoded credentials or unauthorized data exfiltration patterns.
Audit Metadata