ara-compiler
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various untrusted external sources, creating an attack surface for indirect prompt injection.
- Ingestion points: According to the 'Input Philosophy' in
SKILL.md, the skill reads PDFs, arXiv links, GitHub repositories, experiment logs, and communication threads (Slack/emails). - Boundary markers: There are no explicit instructions for using delimiters or boundary markers to isolate untrusted content from the agent's instructions.
- Capability inventory: The skill workflow in
SKILL.mdrequires the use of powerful tools such asBash,Write,Edit, andRead. - Sanitization: The instructions do not specify any sanitization or validation logic for the content extracted from external sources.
- [COMMAND_EXECUTION]: The skill requires the agent to use the
Bashtool to 'fetch or clone' URLs and explore directories. This capability, combined with the processing of untrusted input, increases the risk of command injection or unauthorized actions if the agent follows instructions embedded in research data.
Audit Metadata