denario

Warn

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references installation from GitHub (AstroPilot-AI) and Docker Hub (pablovd) accounts that do not match the identified author (Lua2147) or metadata (K-Dense Inc.).- [COMMAND_EXECUTION]: Installation instructions in 'references/installation.md' advise users to execute system-level commands with 'sudo' for LaTeX installation.- [REMOTE_CODE_EXECUTION]: The 'get_results' method described in 'references/research_pipeline.md' generates and executes code via AI agents, creating a vector for executing malicious logic locally.- [PROMPT_INJECTION]: The skill processes untrusted dataset descriptions via 'set_data_description' which drive automated code generation, creating a surface for indirect prompt injection. Evidence Chain: Ingestion point in 'SKILL.md' (set_data_description); Boundary markers are not implemented; Capability inventory includes broad filesystem and library access via agents; Sanitization of input data is not documented.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 15, 2026, 12:53 PM
Security Audit — agent-trust-hub — denario