smart-sourcing
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill utilizes the WebSearch tool, which introduces a surface for indirect prompt injection from untrusted external web content.
- Ingestion points: The skill implementation involves results from the WebSearch tool.
- Boundary markers: No specific delimiters or boundary instructions are provided to the agent for search results.
- Capability inventory: The skill is limited to WebSearch and has no access to the local file system or sensitive system commands.
- Sanitization: No validation or sanitization logic for external data is present.
- [Prompt Injection] (SAFE): No instructions were found that attempt to bypass safety guidelines, reveal system prompts, or override core instructions.
- [Data Exfiltration] (SAFE): There are no patterns involving hardcoded credentials, sensitive file path access, or unauthorized network transmissions.
Audit Metadata