deep-research
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill workflow involves executing several shell commands to manage directories, generate images, and convert document formats.
- Evidence:
SKILL.mdcontains instructions to executemkdir,python .opencode/skills/image-service/scripts/research_image.py,pandoc, andpython .opencode/skills/deep-research/scripts/format_docx.py. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it ingests untrusted data from external sources and incorporates it into subsequent shell command arguments.
- Ingestion points: Untrusted technical content is retrieved via the
webfetchtool and web search results from theTasktool, as specified inSKILL.md. - Boundary markers: There are no instructions to use delimiters or "ignore embedded instructions" warnings for the external data being processed.
- Capability inventory: The skill is capable of performing shell command execution and file system write operations across all of its research and formatting steps.
- Sanitization: The instructions lack explicit logic for escaping or validating external content before it is interpolated into shell command flags, such as the
-n(name) and-c(content) arguments for the image generation script.
Audit Metadata