ara-research-manager
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill captures the entire conversation history and existing research files to extract significant research events like decisions and claims. This ingestion process is susceptible to indirect prompt injection if the conversation contains malicious instructions from untrusted sources, which could then be written into persistent storage files (e.g., exploration_tree.yaml, claims.md). These artifacts could influence the behavior of other agents or tools that process them in the future. Ingestion points: Conversation history and existing ARA files. Boundary markers: Absent. Capability inventory: File system writes and directory creation. Sanitization: None identified.
- [COMMAND_EXECUTION]: The skill uses shell commands to initialize its workspace by creating a complex directory structure. While the paths are static and the operation is restricted to the local filesystem, it utilizes direct command-line execution for environment setup. Evidence: mkdir -p command used in the Initialization section of SKILL.md.
Audit Metadata