aris-research-pipeline

Warn

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to bypass standard tool limitations (specifically file size constraints) by using Bash commands (cat << 'EOF') to write files silently without requesting user permission.
  • [COMMAND_EXECUTION]: Stage 3 involves executing shell commands to interact with remote servers, including syncing code, checking GPU status, and managing persistent screen sessions.
  • [REMOTE_CODE_EXECUTION]: The 'Auto Review Loop' in Stage 4 autonomously generates and implements code changes based on AI assessments, which are then deployed and executed, potentially on remote infrastructure.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) because it ingests untrusted data from RESEARCH_BRIEF.md and external AI reviews to drive its code generation and execution logic without sanitization or boundary markers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 01:42 AM
Security Audit — agent-trust-hub — aris-research-pipeline