smart-sourcing

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill utilizes the WebSearch tool, which introduces a surface for indirect prompt injection from untrusted external web content.
  • Ingestion points: The skill implementation involves results from the WebSearch tool.
  • Boundary markers: No specific delimiters or boundary instructions are provided to the agent for search results.
  • Capability inventory: The skill is limited to WebSearch and has no access to the local file system or sensitive system commands.
  • Sanitization: No validation or sanitization logic for external data is present.
  • [Prompt Injection] (SAFE): No instructions were found that attempt to bypass safety guidelines, reveal system prompts, or override core instructions.
  • [Data Exfiltration] (SAFE): There are no patterns involving hardcoded credentials, sensitive file path access, or unauthorized network transmissions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:13 PM