skills/danielmiessler/lifeos/Research/Gen Agent Trust Hub

Research

Fail

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The SKILL.md file contains a mandatory directive forcing the agent to execute a curl POST command targeting a local port (http://localhost:31337/notify) immediately upon invocation. This represents an unauthenticated interaction with local system services that can be used for local probing or exploitation.
  • [COMMAND_EXECUTION]: Several workflows, including StandardResearch.md and ExtensiveResearch.md, provide bash snippets for parallel URL verification. These snippets use shell loops to execute curl on agent-extracted strings, which creates a significant risk of shell command injection if the URLs found by the agents contain shell metacharacters.
  • [DATA_EXFILTRATION]: The skill mandates a URL verification protocol that uses curl to check the status of all research links. This pattern is highly susceptible to Server-Side Request Forgery (SSRF) attacks, where an agent could be tricked into accessing sensitive internal network resources or cloud metadata endpoints (e.g., 169.254.169.254).
  • [PROMPT_INJECTION]: The skill uses aggressive mandatory triggers and overrides (e.g., 'No exceptions', 'MUST execute this command immediately') designed to force specific agent behaviors and bypass standard decision-making processes.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality relies on ingesting and processing large volumes of untrusted data from platforms like Reddit, X (Twitter), YouTube, and general web scraping. This provides a massive surface for indirect prompt injection, where attackers can embed instructions in web content to manipulate the agent's research synthesis.
  • [REMOTE_CODE_EXECUTION]: The skill contains multiple executable scripts (ClaudeResearch.md using Node.js child_process, and various .mjs workflow scripts) that are dynamically invoked. While part of the intended framework, this introduces risks associated with executing locally generated or modified script content.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 15, 2026, 06:48 PM
Security Audit — agent-trust-hub — Research