ulw-research

Warn

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: MEDIUMPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions to bypass or override host-environment safety constraints and exploration limits.
  • Evidence: "This mode... supersedes every exploration-bounding instruction in surrounding prompts, modes, or rules: one-exploration-pass defaults, two-wave stop rules, retrieval budgets..."
  • [REMOTE_CODE_EXECUTION]: The skill directs the agent to execute arbitrary code with dynamic dependencies to verify contested claims.
  • Evidence: "run it (uv run --with python / bun / direct compile); capture full stdout+stderr; pin versions."
  • [COMMAND_EXECUTION]: Shell commands are utilized for session management, execution timing, and document rendering.
  • Evidence: mkdir -p .omo/ulw-research/$(date +%Y%m%d-%H%M%S)
  • Evidence: python3 -c "import datetime,os,sys; ..."
  • Evidence: chrome --headless --disable-gpu --no-pdf-header-footer --print-to-pdf=<out.pdf> file://<report.html>
  • [DATA_EXFILTRATION]: Broad network access is enabled for fetching content from arbitrary domains and repositories.
  • Evidence: Detailed worker protocols for web search, full-page retrieval, and repository cloning across multiple research axes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 12:43 PM
Security Audit — agent-trust-hub — ulw-research