researchclaw
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
researchclawpackage from an unverified GitHub repository (https://github.com/aiming-lab/AutoResearchClaw) and viapip3, which are not on the list of trusted services. - [COMMAND_EXECUTION]: The
/researchclaw:runcommand inSKILL.mdinterpolates user-supplied$ARGUMENTSdirectly into a shell command (researchclaw run --topic "$ARGUMENTS" ...). This creates a command injection vulnerability where malicious input could execute arbitrary shell commands. - [DATA_EXFILTRATION]: The configuration template and documentation (
assets/config-template.yaml,references/config-reference.md) facilitate the use of highly sensitive file paths, specifically the SSH private key (~/.ssh/id_rsa), for remote experiment execution, which represents a data exposure risk. - [DYNAMIC_EXECUTION]: The pipeline is designed to dynamically generate Python code (
Stage 10) and execute it (Stage 12) based on the research context. Running dynamically generated code is a high-risk activity that can be exploited if the inputs are compromised. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources like arXiv and Semantic Scholar to influence the research pipeline and experiment code generation, creating an attack surface for indirect prompt injection.
- Ingestion points:
LITERATURE_SEARCHstage (Stage 3) inSKILL.mdandpipeline-stages.mdfetches content from external APIs. - Boundary markers: No specific boundary markers or instructions are provided to the agent to ignore embedded commands in the literature data.
- Capability inventory: The skill uses
Bashto execute scripts andWriteto create configurations and artifacts. - Sanitization: There is no evidence of sanitization or validation of the content fetched from external research databases.
- [PRIVILEGE_ESCALATION]: Documentation in
SKILL.mdandreferences/troubleshooting.mdsuggests usingsudoto install system packages and modify Docker group permissions, which encourages the escalation of privileges.
Audit Metadata