you-research
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a router and knowledge base for research services. It provides logical flows for searching, synthesizing information, and managing API interactions without attempting to override system safety protocols.\n- [EXTERNAL_DOWNLOADS]: The documentation references official Node.js packages including @x402/fetch, @x402/evm, @x402/extensions, and viem required for implementing the x402 payment protocol. These are recognized as functional requirements for the skill's purpose and originate from well-known sources.\n- [DATA_EXFILTRATION]: While the skill manages sensitive API keys and cryptographic signatures, it incorporates explicit security guardrails. It instructs the agent to validate that result URLs remain on the authorized vendor domain (https://api.you.com) to prevent the exfiltration of proof-of-wallet signatures to unauthorized third-party hosts.\n- [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection risks by instructing the agent to treat all web-retrieved content as 'untrusted evidence' rather than instructions. This establishes a clear boundary between processed data and the agent's control flow.
Audit Metadata