auto-research
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill workflow (Steps 2, 3, and 5) instructs the agent to define and run evaluation commands, tasks, and architectural spikes to measure artifact performance. This creates a functional requirement for the agent to execute shell commands based on the project context.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data which could contain malicious instructions. (1) Ingestion points: Workflow Step 1 in SKILL.md directs the agent to read objectives, user feedback, project instructions, and existing research records. (2) Boundary markers: The instructions do not define specific delimiters or 'ignore' instructions for the external content being processed. (3) Capability inventory: The skill workflow explicitly uses command execution capabilities (Step 2: 'Record the evaluation command', Step 3: 'Run the unchanged artifact', Step 5: 'Test one hypothesis') to interact with the environment. (4) Sanitization: There are no instructions for sanitizing or validating the commands or artifacts before execution.
- [PROMPT_INJECTION]: Step 8 of the workflow ('Continue without asking whether to proceed after each experiment') instructs the agent to override typical interactive confirmation patterns to maintain an autonomous research loop.
Audit Metadata