x9-research

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust evidence-based research methodology focusing on primary sources and conflict resolution. It includes defensive validation scripts to verify that generated research reports meet structural and safety requirements (e.g., no external runtime scripts, correct metadata, and proper language tagging).
  • [COMMAND_EXECUTION]: The references/html-reports.md file instructs the agent to run a local validation script (python3 <x9-research-directory>/scripts/validate_html.py). This is a standard project-specific tool execution intended for quality assurance of the skill's own outputs and does not involve arbitrary or malicious shell execution.
  • [REMOTE_CODE_EXECUTION]: No remote code execution was detected. The Python scripts (validate_html.py and its regression tests) are static files provided within the skill's own directory structure for local validation purposes.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were identified. The skill explicitly forbids external network dependencies, trackers, or images in its HTML output requirements, as detailed in references/html-reports.md and enforced by scripts/validate_html.py.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 07:40 AM
Security Audit — agent-trust-hub — x9-research