skills/zzafergok/skills/deep-research/Gen Agent Trust Hub

deep-research

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's operations are consistent with its documented purpose of technical research and professional documentation generation. No unauthorized data access, persistence mechanisms, or obfuscated payloads were detected.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted data from external sources and interpolates it into prompts for research sub-agents during deep investigations. \n
  • Ingestion points: WebSearch tool output from community forums and GitHub repositories (SKILL.md). \n
  • Boundary markers: Absent. The task prompts for sub-agents do not use specific delimiters or instructions to separate untrusted research data from core instructions. \n
  • Capability inventory: Task tool for sub-agent spawning, Grep tool for documentation search, and WebSearch tool for external lookup. \n
  • Sanitization: Absent. External content is synthesized directly into findings and sub-agent contexts without explicit filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 02:03 AM
Security Audit — agent-trust-hub — deep-research