skills/openlair/dr-claw/ds-idea/Gen Agent Trust Hub

ds-idea

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) due to its core functionality of ingesting unverified external data.
  • Ingestion points: The agent is instructed to use artifact.arxiv(...) for full-text paper reading, perform web searches for discovery, and inspect "implementation repositories" for nearby methods (referenced in SKILL.md and references/related-work-playbook.md).
  • Boundary markers: There are no specific instructions for the agent to use XML tags, delimiters, or "ignore embedded instructions" warnings when interpolating content from external papers or repositories into its reasoning context.
  • Capability inventory: The agent has the capability to write this processed content to long-term memory (memory.write(...)), interact with the user via reports (artifact.interact(...)), and generate persistent research directions (artifact.submit_idea(...)).
  • Sanitization: The instructions do not mandate any validation or sanitization of content retrieved from the web or arXiv before it is used to shape research hypotheses or stored in the quest's permanent record.
  • [SAFE]: The skill package contains no executable code, scripts, or binaries. All files are instructional markdown or JSON templates used for structuring research artifacts. No obfuscated code or unauthorized network communication patterns were detected within the skill's own instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 01:42 AM
Security Audit — agent-trust-hub — ds-idea