run
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests historical experiment data which could influence its logic.
- Ingestion points: Reads from .autoresearch/ files (SKILL.md, Step 2/3).
- Boundary markers: None present.
- Capability inventory: Writes to files and executes shell commands (Step 4/5).
- Sanitization: No sanitization of ingested content.
- [COMMAND_EXECUTION]: The skill executes system commands and local scripts to manage the experiment lifecycle.
- Evidence: Invokes git commands and python scripts for setup and execution.
Audit Metadata