search-strategy
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or persistence mechanisms were detected in the skill's instructions.
- [NO_CODE]: The skill consists solely of markdown-based instructions for query decomposition and search synthesis, containing no executable scripts or code files.
- [PROMPT_INJECTION]: No direct prompt injection or safety guideline bypass attempts were found. The skill describes standard enterprise search workflows.
- [DATA_EXPOSURE]: The skill outlines logic for searching internal tools (chat, wiki, project trackers) but does not contain hardcoded credentials or logic to exfiltrate data to external domains.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data.
- Ingestion points: Data retrieved from external sources like
~~chat,~~knowledge base, and~~project tracker(SKILL.md). - Boundary markers: None explicitly defined in the strategy to separate retrieved content from instructions.
- Capability inventory: The agent uses search tool calls to aggregate and synthesize information.
- Sanitization: No specific sanitization or filtering logic is prescribed for the retrieved data.
Audit Metadata