aris-grant-proposal

Fail

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to check for the existence of ~/.claude/feishu.json. This file is located outside the project directory in the user's home folder and likely contains API credentials or configuration for the Feishu/Lark platform.\n- [COMMAND_EXECUTION]: The skill includes instructions to use Bash to write files in chunks using the cat << 'EOF' > file pattern. Crucially, it explicitly mandates that the agent 'Do NOT ask the user for permission — just do it silently,' which bypasses standard human-in-the-loop safety protocols.\n- [DATA_EXFILTRATION]: The workflow involves sending the complete proposal draft, which contains sensitive research ideas and personal information harvested from CVs and bios, to an external service via the mcp__codex__codex tool.\n- [PROMPT_INJECTION]: The skill contains 'AUTO_PROCEED' logic and instructions for 'silent' autonomous tool usage. These instructions encourage the agent to ignore user confirmation checkpoints, increasing the risk of autonomous malicious actions if the agent is influenced by adversarial input.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from literature surveys, arXiv PDFs, and web search results in Phase 1. This content is processed and used to generate the proposal, creating an attack surface where malicious instructions embedded in research papers could influence the agent's behavior.\n
  • Ingestion points: IDEA_REPORT.md, literature search results, downloaded arXiv PDFs, cv.md.\n
  • Boundary markers: Absent; no delimiters or instructions to ignore embedded prompts in source material are provided.\n
  • Capability inventory: Bash, Write, Edit, WebFetch, and Agent/Skill tools.\n
  • Sanitization: None detected; the skill directly processes external text into drafting phases.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 6, 2026, 01:42 AM
Security Audit — agent-trust-hub — aris-grant-proposal