autoresearch-loop

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes a workflow for processing and refining arbitrary 'instruction atoms' and 'evaluation suites', which creates a surface for indirect prompt injection if the processed content contains malicious instructions intended to influence the agent's behavior during the evaluation loop.
  • Ingestion points: SKILL.md ('Select one eligible atom') and references/eval-suite.md ('prompts, assertions, fixtures').
  • Boundary markers: The skill requires freezing the suite digest for integrity (references/eval-suite.md) and mandates an isolation boundary for the target atom within the harness adapter (references/harness-adapter.md).
  • Capability inventory: The documentation specifies that a harness adapter must 'execute the frozen suite' and report measurements. No actual implementation scripts or subprocess calls are provided within the skill files themselves.
  • Sanitization: The methodology emphasizes immutable audit trails and digest verification but does not describe explicit content sanitization or filtering for the instruction atoms or evaluation suite inputs.
  • [NO_CODE]: The skill consists entirely of markdown documentation and JSON evaluation data; no executable scripts, binaries, or platform-specific code were found within the provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 12:18 AM
Security Audit — agent-trust-hub — autoresearch-loop