workbench-research

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. 1. Ingestion points: untrusted data enters via 'primary sources', 'official docs', and 'source URLs' as specified in SKILL.md. 2. Boundary markers: absent; the instructions do not specify delimiters or warnings to ignore embedded instructions within processed data. 3. Capability inventory: mentions use of 'live commands', 'rg', and 'jq' to analyze systems (SKILL.md). 4. Sanitization: absent; there are no instructions for filtering or validating external content before analysis.
  • [DATA_EXFILTRATION]: The skill explicitly instructs the agent to avoid copying secrets or private tokens into research reports, which is a positive security practice.
  • [SAFE]: The skill is entirely instructional and contains no executable code, remote script downloads, or obfuscated elements.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 11:56 PM