external-context
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external web content, which inherently introduces a surface for indirect prompt injection if external sources contain instructions intended to influence the LLM.
- Ingestion points: Data is retrieved from the internet via
WebSearchandWebFetchtools used by sub-agents as defined inSKILL.md. - Boundary markers: The instructions do not specify explicit delimiters (e.g., XML tags or special tokens) to separate fetched content from the synthesis logic.
- Capability inventory: The skill uses the
Tasktool to spawn sub-agents and performs text synthesis; it does not have direct access to system commands or file writing in this context. - Sanitization: No explicit sanitization or validation of the retrieved web content is performed before synthesis.
Audit Metadata