aris-research-refine
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from local research documents and web search results. \n
- Ingestion points: Files in
papers/andliterature/directories; results fromWebSearchandWebFetchtools.\n - Boundary markers: Absent; no instructions to ignore embedded commands in sourced content were detected.\n
- Capability inventory: The skill utilizes
Bash,Write,Edit, and network tools.\n - Sanitization: None; the skill interpolates processed content directly into prompts for the reviewer model.\n- [COMMAND_EXECUTION]: The skill uses the
Bashtool for routine file management and state persistence, including a specific instruction to usecat << 'EOF'for handling large file writes.\n- [EXTERNAL_DOWNLOADS]: UtilizesWebSearchandWebFetchto acquire external research papers and grounding material as part of its core research function.\n- [SAFE]: The core logic, involving an iterative review loop with an external model (GPT-5.4 via Codex MCP), aligns with the skill's stated purpose of research refinement and represents expected functionality for the 'OpenLAIR' vendor context.
Audit Metadata