search-strategy

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or persistence mechanisms were detected in the skill's instructions.
  • [NO_CODE]: The skill consists solely of markdown-based instructions for query decomposition and search synthesis, containing no executable scripts or code files.
  • [PROMPT_INJECTION]: No direct prompt injection or safety guideline bypass attempts were found. The skill describes standard enterprise search workflows.
  • [DATA_EXPOSURE]: The skill outlines logic for searching internal tools (chat, wiki, project trackers) but does not contain hardcoded credentials or logic to exfiltrate data to external domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data.
  • Ingestion points: Data retrieved from external sources like ~~chat, ~~knowledge base, and ~~project tracker (SKILL.md).
  • Boundary markers: None explicitly defined in the strategy to separate retrieved content from instructions.
  • Capability inventory: The agent uses search tool calls to aggregate and synthesize information.
  • Sanitization: No specific sanitization or filtering logic is prescribed for the retrieved data.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 02:03 AM
Security Audit — agent-trust-hub — search-strategy