anycap-deepresearch

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is centered around the anycap CLI tool, which is a legitimate vendor resource provided by the author anycap-ai. All core functionality, including search, crawling, and publishing, is mediated through this authenticated interface.
  • [COMMAND_EXECUTION]: The workflow utilizes standard shell utilities like mkdir, tee, and jq for workspace organization and data processing. These commands are used in a manner consistent with the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: The skill performs legitimate external data retrieval using anycap search and crawl commands. It also uses curl to download original image assets from research sources for use in reports.
  • [PROMPT_INJECTION]: The skill processes untrusted content from web searches, page crawls, and media analysis tools, creating an indirect prompt injection surface. 1. Ingestion points: Web content retrieved via anycap search, crawl, and media-read actions (references/02-gather.md). 2. Boundary markers: No specific delimiters or instruction-bypass warnings are explicitly defined for the AI when processing the external content. 3. Capability inventory: Filesystem writes, anycap drive upload, and anycap page deploy (references/05-deliver.md). 4. Sanitization: No explicit content sanitization is described. The risk is minimized by the skill's primary focus on research and its mandatory instructions for human-in-the-loop clarification and multi-source verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 08:44 AM