research-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process 'research artifacts', 'raw-result paths', and external documents (e.g.,
RESEARCH_REVIEW_REQUEST.md) provided by the user. While it incorporates specific 'SCOPE LIMITS' in the reviewer prompt to restrict the AI's behavior, it remains vulnerable to malicious instructions embedded within the research data it analyzes, particularly when those artifacts influence high-capability tool calls likemcp__codex__codex. This fits the pattern of Tool Output Poisoning and Direct Injection into processed data. - [REMOTE_CODE_EXECUTION]: Note that while the skill references
mcp__codexservers and executable bash tools, these are configured as allowed tools by the system and are part of the intended researcher-agent workflow. The execution is mediated through the agent's MCP interface rather than unauthorized shell piping.
Audit Metadata