ccdawn-ai-research-loop

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute research experiments, modify code, and evaluate results within a defined "Context Boundary". These operations are restricted to an "Allowed Action" set and include a "Baseline Gate" to verify reproducibility before proceeding, mitigating risks associated with arbitrary command execution.- [EXTERNAL_DOWNLOADS]: Documentation references established research repositories from reputable sources including Microsoft, the Vector Institute, and known research frameworks for design inspiration. These references serve as methodological guides and do not involve insecure remote code execution patterns.- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests content from external repositories, papers, and logs to inform its research loop.
  • Ingestion points: External code repositories, research papers, and log files mentioned in SKILL.md.
  • Boundary markers: Explicitly defined "Context Boundary", "Allowed Action" limits, and "Output Contract" are used to scope agent behavior.
  • Capability inventory: Includes code modification and experiment execution capabilities facilitated through internal tooling (SKILL.md, ccdawn-score-loop).
  • Sanitization: Relies on structured "Research Contracts" and the "Baseline Gate" validation process rather than explicit content filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 09:31 AM
Security Audit — agent-trust-hub — ccdawn-ai-research-loop