web-research

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data enters the agent context through the WebSearch and WebFetch tools as described in Step 2 and Step 3 of SKILL.md.\n
  • Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing content fetched from the web.\n
  • Capability inventory: The agent possesses Write, TaskCreate, and WebSearch capabilities, which could allow it to perform unintended actions or modify local files based on malicious content found in search results.\n
  • Sanitization: There is no evidence of sanitization, escaping, or validation of the external content before it is triaged or used to build the source map.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 08:38 AM