autoresearch
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates as a deterministic simulator for research contracts. It uses canned data fixtures and basic arithmetic for analysis, with no external network calls, file system modifications, or dynamic code execution detected.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests user input and interpolates it into hypothesis templates. While this creates a potential surface for indirect prompt injection, the risk is negligible as the skill lacks dangerous capabilities or sinks that would interpret these strings as executable commands or sensitive data requests.\n
- Ingestion points: The topic parameter in agent.py derived from request.query.user_input.\n
- Boundary markers: None present in the interpolation templates.\n
- Capability inventory: No subprocess calls, network operations, file writes, or dynamic execution identified in agent.py or tools.py.\n
- Sanitization: No sanitization is performed on the input topic before interpolation.
Audit Metadata