autoresearch
Warn
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions "NEVER STOP unless manually interrupted" and "don't stop to ask. Run until interrupted" explicitly direct the agent to bypass operational constraints and human-in-the-loop verification processes for command execution and file modification.\n- [COMMAND_EXECUTION]: The skill requires the execution of arbitrary shell commands for running experiments and extracting metrics, which are performed autonomously within a continuous loop without user oversight.\n- [REMOTE_CODE_EXECUTION]: The skill follows a dynamic execution pattern where it iteratively modifies target source code or configuration files and then immediately executes the modified content, creating a self-modifying execution cycle.
Audit Metadata