research-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of markdown documentation and templates. It does not include any executable scripts, binaries, or commands that interact with the host system beyond the intended use of a web search tool.- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to gather and analyze external data from the web, which constitutes an indirect prompt injection surface.\n
- Ingestion points: Search results retrieved from the
web-searchtool during Phase 2 (Execution).\n - Boundary markers: Absent; the skill does not instruct the agent to use specific delimiters or to ignore potential instructions embedded in external search results.\n
- Capability inventory: The skill relies on the
web-searchtool for data collection.\n - Sanitization: No sanitization or content validation for the retrieved search results is prescribed in the workflow.\n
- Context: This risk is inherent to any research-oriented tool that processes untrusted third-party content.
Audit Metadata