aeon-autoresearch
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill generates new variations of skill logic and overwrites existing files in its evolve mode, which constitutes runtime modification of agent capabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests other local skill files as untrusted data, creating a surface where malicious instructions in a target skill could influence the evolution logic and lead to the generation of compromised skill variations.\n
- Ingestion points: Reads target skill files from the local filesystem as identified in the SKILL.md inputs.\n
- Boundary markers: No explicit delimiter or instruction-isolation markers are defined in the variation generation process.\n
- Capability inventory: Reads the filesystem, writes and overwrites skill files, and performs git branching operations.\n
- Sanitization: The skill relies on weighted scoring rubrics and safety aborts rather than explicit content sanitization or verification of ingested data.\n- [EXTERNAL_DOWNLOADS]: References installation and updates from the author's GitHub repository. This is documented as standard behavior for skill management within the BankrBot ecosystem.
Audit Metadata