industry-research
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
recoup researchCLI tool to perform research tasks. These commands are executed with various arguments including artist names, entity names, and URLs. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection risk through its web intelligence features. * Ingestion points: External data is fetched using
recoup research extract,web, andreportcommands in SKILL.md. * Boundary markers: There are no specific delimiters or instructions provided to the agent to treat extracted content as untrusted. * Capability inventory: The agent has the ability to execute CLI commands and write research results to the filesystem. * Sanitization: No sanitization or validation steps are defined for the data retrieved from external web sources.
Audit Metadata