ai-deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a searcher-verifier architecture designed to ingest data from external web sources. This ingestion of untrusted content through tools like Claude with web search or Google Search represents a potential surface for indirect prompt injection.
  • Ingestion points: Web search results are processed by the Searcher subagent to build the research ledger as described in references/agentic-research-loop-architecture.md.
  • Boundary markers: The architecture enforces P4 (Verifier subagent isolation), which ensures the verifier only reads the finalized SourceLedger and has no access to the researcher's browser history or context.
  • Capability inventory: The skill writes JSONL and Markdown artifacts to the local filesystem and executes a local citation verification script (scripts/citation_verifier.py).
  • Sanitization: The workflow includes P9 (Hostile-source detection) to filter adversarial SEO or AI-generated content before it is recorded in the ledger, and P5 (Freshness-window sourcing) to reject stale information.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and tool repositories from trusted organizations including OpenAI, Google, Anthropic, xAI, and Perplexity. These references are provided to assist in configuring native deep-research agents and understanding API capabilities.
  • [COMMAND_EXECUTION]: The skill includes a Python script (scripts/citation_verifier.py) and instructions for using it to perform automated citation checking. The script uses only standard library modules to process local JSONL research data, verifying that claims match supporting quotes without external network access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-deep-research