ops-darpa
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches data from official DARPA RSS feeds (darpa.mil) and the Grants.gov API (api.grants.gov). These are well-known and trusted government sources used strictly for their intended purpose.
- [COMMAND_EXECUTION]: The analyze and generate commands use subprocess.run to execute local tools (pdftotext) and related skills (create-paper). These calls are implemented using argument lists, which prevents shell injection vulnerabilities.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads user-provided BAA files and proposal directories for analysis. No sensitive system files, environment variables, or hardcoded credentials are accessed or exposed.
- [PROMPT_INJECTION]: The skill processes untrusted external data from RSS feeds and government APIs. While this represents a surface for indirect prompt injection, the sources are trusted government repositories, and the skill performs basic sanitization (HTML stripping) before processing.
Audit Metadata