aris-research-refine

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from local research documents and web search results. \n
  • Ingestion points: Files in papers/ and literature/ directories; results from WebSearch and WebFetch tools.\n
  • Boundary markers: Absent; no instructions to ignore embedded commands in sourced content were detected.\n
  • Capability inventory: The skill utilizes Bash, Write, Edit, and network tools.\n
  • Sanitization: None; the skill interpolates processed content directly into prompts for the reviewer model.\n- [COMMAND_EXECUTION]: The skill uses the Bash tool for routine file management and state persistence, including a specific instruction to use cat << 'EOF' for handling large file writes.\n- [EXTERNAL_DOWNLOADS]: Utilizes WebSearch and WebFetch to acquire external research papers and grounding material as part of its core research function.\n- [SAFE]: The core logic, involving an iterative review loop with an external model (GPT-5.4 via Codex MCP), aligns with the skill's stated purpose of research refinement and represents expected functionality for the 'OpenLAIR' vendor context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 01:42 AM
Security Audit — agent-trust-hub — aris-research-refine