search-expert

Pass

Audited by Gen Agent Trust Hub on Feb 18, 2026

Risk Level: SAFE
Full Analysis
  • Indirect Prompt Injection (LOW): This skill has an attack surface for indirect prompt injection because it processes untrusted data from the web using zai-web-search.
  • Ingestion points: Web search results via zai-web-search:*.
  • Boundary markers: None present.
  • Capability inventory: Synthesis and summarization. No file-system, command-line, or general network-send capabilities are present.
  • Sanitization: None specified.
  • General Security (SAFE): No evidence of credential theft, data exfiltration, or obfuscation was found. The skill is restricted to its stated toolset.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 18, 2026, 07:36 PM