researchclaw

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the researchclaw package from an unverified GitHub repository (https://github.com/aiming-lab/AutoResearchClaw) and via pip3, which are not on the list of trusted services.
  • [COMMAND_EXECUTION]: The /researchclaw:run command in SKILL.md interpolates user-supplied $ARGUMENTS directly into a shell command (researchclaw run --topic "$ARGUMENTS" ...). This creates a command injection vulnerability where malicious input could execute arbitrary shell commands.
  • [DATA_EXFILTRATION]: The configuration template and documentation (assets/config-template.yaml, references/config-reference.md) facilitate the use of highly sensitive file paths, specifically the SSH private key (~/.ssh/id_rsa), for remote experiment execution, which represents a data exposure risk.
  • [DYNAMIC_EXECUTION]: The pipeline is designed to dynamically generate Python code (Stage 10) and execute it (Stage 12) based on the research context. Running dynamically generated code is a high-risk activity that can be exploited if the inputs are compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources like arXiv and Semantic Scholar to influence the research pipeline and experiment code generation, creating an attack surface for indirect prompt injection.
  • Ingestion points: LITERATURE_SEARCH stage (Stage 3) in SKILL.md and pipeline-stages.md fetches content from external APIs.
  • Boundary markers: No specific boundary markers or instructions are provided to the agent to ignore embedded commands in the literature data.
  • Capability inventory: The skill uses Bash to execute scripts and Write to create configurations and artifacts.
  • Sanitization: There is no evidence of sanitization or validation of the content fetched from external research databases.
  • [PRIVILEGE_ESCALATION]: Documentation in SKILL.md and references/troubleshooting.md suggests using sudo to install system packages and modify Docker group permissions, which encourages the escalation of privileges.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 08:23 AM
Security Audit — agent-trust-hub — researchclaw