run

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests historical experiment data which could influence its logic.
  • Ingestion points: Reads from .autoresearch/ files (SKILL.md, Step 2/3).
  • Boundary markers: None present.
  • Capability inventory: Writes to files and executes shell commands (Step 4/5).
  • Sanitization: No sanitization of ingested content.
  • [COMMAND_EXECUTION]: The skill executes system commands and local scripts to manage the experiment lifecycle.
  • Evidence: Invokes git commands and python scripts for setup and execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:34 PM
Security Audit — agent-trust-hub — run