autoresearch
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements a self-modifying loop that targets
SKILL.mdfiles. It analyzes failures, mutates the prompt instructions, and then executes the modified skill repeatedly to measure improvements. This involves generating and running executable agent instructions at runtime. - [PROMPT_INJECTION]: The skill contains explicit instructions to override standard human-in-the-loop safety patterns. It states "NEVER STOP. Once the loop starts, do not pause to ask the user if you should continue" and instructs the agent to run "autonomously until stopped," which may lead to unintended actions or resource consumption without user oversight.
- [INDIRECT_PROMPT_INJECTION]: The skill represents a significant attack surface for indirect injection as it ingests untrusted data from external
SKILL.mdfiles, user-provided test inputs, and files in thereferences/directory. - Ingestion points: Target
SKILL.mdfiles,references/*.mdfiles, and user-supplied "Test inputs". - Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded malicious prompts within the files it processes.
- Capability inventory: The skill has the ability to write to the local filesystem (
results.tsv,results.json,dashboard.html), modify other skill files, execute shell commands (open), and recursively invoke other agent skills. - Sanitization: There is no evidence of sanitization or validation of the content read from external skills before it is executed or used to mutate instructions.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute system commands like
open dashboard.htmlto launch local files in the user's browser. - [EXTERNAL_DOWNLOADS]: The skill generates a dashboard that attempts to load
Chart.jsfrom an external Content Delivery Network (CDN) at runtime.
Audit Metadata