deep-research

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill workflow involves executing several shell commands to manage directories, generate images, and convert document formats.
  • Evidence: SKILL.md contains instructions to execute mkdir, python .opencode/skills/image-service/scripts/research_image.py, pandoc, and python .opencode/skills/deep-research/scripts/format_docx.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it ingests untrusted data from external sources and incorporates it into subsequent shell command arguments.
  • Ingestion points: Untrusted technical content is retrieved via the webfetch tool and web search results from the Task tool, as specified in SKILL.md.
  • Boundary markers: There are no instructions to use delimiters or "ignore embedded instructions" warnings for the external data being processed.
  • Capability inventory: The skill is capable of performing shell command execution and file system write operations across all of its research and formatting steps.
  • Sanitization: The instructions lack explicit logic for escaping or validating external content before it is interpolated into shell command flags, such as the -n (name) and -c (content) arguments for the image generation script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — deep-research