deepresearch
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its core workflow of fetching and processing untrusted web content. 1. Ingestion points: External URLs retrieved via the WebFetch tool across all research phases. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the agent prompt scaffolding. 3. Capability inventory: High-capability tools including Bash, Write, and Edit are accessible for local environment manipulation. 4. Sanitization: Fetched data is not validated or filtered before being analyzed by parallel agents.
- [COMMAND_EXECUTION]: Employs the Bash tool to automate local task organization, including creating topic-specific research directories and managing local file storage.
- [EXTERNAL_DOWNLOADS]: Performs web retrieval of technical documentation, security advisories, and academic papers from sources like the National Vulnerability Database (NVD) and arXiv.
Audit Metadata