vs-search
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: The skill defines a search management workflow utilizing vendor-authorized CLI tools. Security is maintained through explicit constraints, such as the Customer Environment Principle, which prevents the agent from autonomously reading local repository source files and requires reliance on user-provided information.\n- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. Untrusted data enters the agent context through search queries (e.g., search run) and dictionary file imports (e.g., dict write-terms). No explicit boundary markers or sanitization steps are defined in the instructions to isolate these inputs. The capability inventory includes execution of shell commands through the vendor CLI and mutation of remote scene configurations. The risk is mitigated by operational constraints that prohibit autonomous file access and mandate validation against product schema.\n- [NO_CODE]: The skill consists solely of markdown instructions and reference files, with no executable scripts or binaries included in the distribution.
Audit Metadata