aris-research-wiki
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection through the ingestion of external research paper metadata.
- Ingestion points: External research data is fetched from sources like arXiv, DBLP, and Semantic Scholar and stored in the 'papers/' directory.
- Boundary markers: The skill uses YAML and Markdown headers for structure, but lacks explicit instructions to treat the ingested data as untrusted or to ignore instructions within that data.
- Capability inventory: The skill utilizes powerful tools including Bash(*), Write, Edit, and Agent interaction, which could be leveraged if an injected prompt is successfully executed.
- Sanitization: There is no mention of sanitization or filtering of the content retrieved from external research databases.
- [EXTERNAL_DOWNLOADS]: The skill fetches research paper metadata from well-known technology services including arXiv, DBLP, and Semantic Scholar to populate the knowledge base.
Audit Metadata