aeon-autoresearch

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves reading the content of other SKILL.md files to generate improved variations. If a target skill contains adversarial instructions designed to subvert the evolution process, the skill could inadvertently generate a malicious version of the target.
  • Ingestion points: Reads the content of a user-specified target skill file.
  • Boundary markers: The skill description does not mention specific delimiters or instructions to ignore embedded prompts during the analysis phase.
  • Capability inventory: The skill has the capability to write to the file system (overwriting SKILL.md files or creating backups) and can create git branches.
  • Sanitization: No specific sanitization or filtering of the target skill's content is described beyond preserving the frontmatter schema.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and applies new agent instructions (SKILL.md variations) at runtime based on its internal theses. This involves the automated creation of new logic which, while scored, represents the deployment of logic not directly authored by the user.
  • [EXTERNAL_DOWNLOADS]: The skill's metadata and catalog configuration point to external sources for installation and documentation.
  • References the provider's GitHub repository: github.com/aaronjmars/aeon.
  • Directs installation from the vendor's repository: github.com/BankrBot/skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — aeon-autoresearch