ara-compiler

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various untrusted external sources, creating an attack surface for indirect prompt injection.
  • Ingestion points: According to the 'Input Philosophy' in SKILL.md, the skill reads PDFs, arXiv links, GitHub repositories, experiment logs, and communication threads (Slack/emails).
  • Boundary markers: There are no explicit instructions for using delimiters or boundary markers to isolate untrusted content from the agent's instructions.
  • Capability inventory: The skill workflow in SKILL.md requires the use of powerful tools such as Bash, Write, Edit, and Read.
  • Sanitization: The instructions do not specify any sanitization or validation logic for the content extracted from external sources.
  • [COMMAND_EXECUTION]: The skill requires the agent to use the Bash tool to 'fetch or clone' URLs and explore directories. This capability, combined with the processing of untrusted input, increases the risk of command injection or unauthorized actions if the agent follows instructions embedded in research data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — ara-compiler