autoresearch

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHPERSISTENCEPROMPT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill instructs the agent to configure persistent operation using the cron.add tool in OpenClaw or the /loop command in Claude Code. This allows the agent to maintain activity and continue research tasks across different sessions without active user oversight.
  • [PROMPT_INJECTION]: Instructions explicitly direct the agent to "Do not ask the user for permission or confirmation" and to act as if the user is unavailable. This pattern bypasses human-in-the-loop safety controls and grants the agent excessive autonomy over the local environment.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external Python packages at runtime, including semanticscholar, arxiv, weasyprint, and playwright, to support data collection and reporting functions.
  • [INDIRECT_PROMPT_INJECTION]: The agent is instructed to process untrusted data from external literature sources like arXiv and Semantic Scholar. This content is stored in the workspace and subsequently read back into the agent's context, creating a surface for indirect instructions to influence agent behavior. Mandatory Evidence Chain: (1) Ingestion points: literature/ folder and web search results; (2) Boundary markers: Absent from the project templates; (3) Capability inventory: Subprocess execution, file system writes, and network-based reporting; (4) Sanitization: No mechanisms provided for validating external content.
  • [DATA_EXFILTRATION]: The skill facilitates the transmission of research findings, plots, and metadata to external communication platforms such as Telegram, WhatsApp, and Slack, posing a risk of sensitive data exposure.
  • [COMMAND_EXECUTION]: The agent is directed to autonomously generate and run code for diverse tasks including model training, experiment execution, and automated report generation via HTML and PDF templates.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — autoresearch