skills/mattpocock/skills/research/Gen Agent Trust Hub

research

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill researches information from external primary sources like documentation and source code, which provides an attack surface for indirect prompt injection. Malicious instructions embedded in external content could be processed by the agent, potentially influencing its subsequent actions or the research findings.
  • Ingestion points: External websites, documentation pages, and code repositories (SKILL.md).
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to ignore embedded instructions (SKILL.md).
  • Capability inventory: The skill is instructed to write findings to a Markdown file in the repository (SKILL.md).
  • Sanitization: Absent. There is no requirement for filtering or escaping content retrieved from external sources before saving it (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:16 PM
Security Audit — agent-trust-hub — research