external-context

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external web content, which inherently introduces a surface for indirect prompt injection if external sources contain instructions intended to influence the LLM.
  • Ingestion points: Data is retrieved from the internet via WebSearch and WebFetch tools used by sub-agents as defined in SKILL.md.
  • Boundary markers: The instructions do not specify explicit delimiters (e.g., XML tags or special tokens) to separate fetched content from the synthesis logic.
  • Capability inventory: The skill uses the Task tool to spawn sub-agents and performs text synthesis; it does not have direct access to system commands or file writing in this context.
  • Sanitization: No explicit sanitization or validation of the retrieved web content is performed before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:34 PM
Security Audit — agent-trust-hub — external-context