ops-darpa

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from official DARPA RSS feeds (darpa.mil) and the Grants.gov API (api.grants.gov). These are well-known and trusted government sources used strictly for their intended purpose.
  • [COMMAND_EXECUTION]: The analyze and generate commands use subprocess.run to execute local tools (pdftotext) and related skills (create-paper). These calls are implemented using argument lists, which prevents shell injection vulnerabilities.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads user-provided BAA files and proposal directories for analysis. No sensitive system files, environment variables, or hardcoded credentials are accessed or exposed.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from RSS feeds and government APIs. While this represents a surface for indirect prompt injection, the sources are trusted government repositories, and the skill performs basic sanitization (HTML stripping) before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ops-darpa