CtrlK
BlogDocsLog inGet started
Tessl Logo

sayed/research-pipeline

Produce a rigorous, verified, fully-cited research report on ANY topic by running a disciplined five-stage pipeline: CLARIFY the question, PLAN (an editable research plan), FAN-OUT parallel search subagents, VERIFY every key claim (cross-source + adversarial + cross-model), then SYNTHESIZE a cited report. Use this WHENEVER the user wants real research rather than a quick answer — "research X", "do a deep dive on Y", "write me a report / brief / literature review on Z", "compare A vs B and back it with sources", "what's the state of the art in …", "investigate …", "find evidence for/against …", "give me a market/landscape/competitor analysis", or any question where being wrong is costly and the answer needs citations. Trigger even when the user does not say the word "research" but clearly needs multi-source, fact-checked, cited output. This is the general-topic web-research orchestrator — not the codebase-to-wiki `deep-research` skill. For a fast single-fact lookup, answer directly instead.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

High risk: the required FAN-OUT SEARCH stage fetches and READs arbitrary public web pages at runtime (WebFetch) and uses their quoted passages as LLM input for the subsequent VERIFY and SYNTHESIZE stages, so outsider-authored free-text from the web can be incorporated into the model context.

Where we found it

arbitrary public web pages (WebFetch)

content-type · 1 site

The FAN-OUT SEARCH stage explicitly instructs subagents to fetch and read arbitrary public web pages via WebFetch, then use the quoted passages as LLM input for the VERIFY and SYNTHESIZE stages.

references/playbook.md

65

- Open and READ the most relevant sources with WebFetch. NEVER report a claim from a search snippet you

Report incorrect finding
Audited
Security analysis
Snyk