autoresearch

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to operate with high autonomy, specifically stating to "NEVER STOP" and "do not pause to ask the user if you should continue" once the loop has started. This reduces human-in-the-loop oversight during the execution of mutated instructions.
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection due to the processing of untrusted data.
  • Ingestion points: The skill reads the content of target SKILL.md files, associated reference documentation, and user-provided test inputs.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potentially malicious instructions embedded within the target skills or test inputs.
  • Capability inventory: The agent has the capability to write to the file system, execute shell commands (e.g., open), and execute other skills.
  • Sanitization: No validation or sanitization logic is present to check the content of the skills being optimized or the test inputs used for evaluation.
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with the host system, such as using the open command on macOS to launch the generated HTML dashboard in a web browser.
  • [EXTERNAL_DOWNLOADS]: The generated dashboard incorporates the Chart.js library from a public CDN for data visualization.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — autoresearch