agent-research-aggregator

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process local AI agent logs, which are considered untrusted data. If these logs contain malicious instructions intended to influence the LLM during the extraction or synthesis phases, the agent could be manipulated.
  • Ingestion points: Files located within AI agent cache directories (e.g., .claude, .cursor, .antigravity, .openclaw) and any user-specified directory scanned by scripts/discover_logs.py.
  • Boundary markers: The synthesis prompt in Phase 3 uses <raw_experiments> XML-style tags to delimit data, but the extraction prompt in Phase 2 does not include strong boundary markers for the raw log text input.
  • Capability inventory: The skill can execute local Python scripts via python commands and write research artifacts to the workspace/ directory.
  • Sanitization: While the extraction and synthesis prompts include instructions to strip PII and credentials, there is no technical sanitization or validation to prevent the LLM from following instructions embedded within the processed logs.
  • [COMMAND_EXECUTION]: The skill relies on several local Python scripts (discover_logs.py, extract_experiments.py, format_po_inputs.py) to perform its tasks. These scripts perform broad filesystem operations, including scanning the home directory (~) for sensitive file patterns, which, while intended for the skill's functionality, requires the user to trust the script logic and the agent's execution of it.
  • [DATA_EXPOSURE]: The discovery script (scripts/discover_logs.py) scans the user's home directory and project roots for log files. Although it includes exclusion lists for known sensitive patterns like .env and .pem files, a broad scan of the home directory increases the risk of accessing or inadvertently processing sensitive data not specifically covered by the filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 08:12 AM
Security Audit — agent-trust-hub — agent-research-aggregator