meta-methodology-research-methodology

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a research methodology that is strictly read-only and evidence-based. It does not include any scripts, executable commands, network requests, or persistence mechanisms. The metadata and referenced files follow best practices for developer tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading external codebase files via search and read tools, which is an ingestion point for untrusted data. The risk is assessed as safe because the methodology enforces a read-only constraint and the skill lacks capabilities for file writing, network exfiltration, or dynamic code execution. 1. Ingestion points: Codebase files accessed via Glob, Grep, and Read tools as defined in SKILL.md. 2. Boundary markers: The methodology requires structured findings with mandatory file:line references to maintain context. 3. Capability inventory: Explicitly read-only; no tools for writing files, network access, or command execution are permitted. 4. Sanitization: Not explicitly defined for input content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:57 PM
Security Audit — agent-trust-hub — meta-methodology-research-methodology