deep-research

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a rigorous research methodology that relies on well-known services (Brave Search, GitHub, Tavily, Exa) for their intended purposes.
  • [COMMAND_EXECUTION]: The skill specifies a standard for using the GitHub CLI (gh api) to retrieve repository structures, metadata, and file contents. This is used as a technical verification method for 'Tier 0' and 'Tier 1' evidence claims.
  • [PROMPT_INJECTION]: The research workflow ingests data from external web sources and public code repositories, creating an indirect prompt injection surface. The skill mitigates this through a mandatory 'Adversarial / Falsification Search' step (Step 7) and a structured output format (Step 10).
  • Ingestion points: Results from Brave, Exa, Tavily, and GitHub search tools.
  • Boundary markers: Output is compartmentalized into an 'Evidence Matrix' and 'Answer' sections.
  • Capability inventory: The skill utilizes search APIs and shell command execution via the GitHub CLI.
  • Sanitization: Verification is performed through cross-validation and explicit searches for contradictory evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 03:42 PM
Security Audit — agent-trust-hub — deep-research