arxiv
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's instructions require the agent to build shell commands by directly interpolating user-provided inputs into strings, such as
python3 "$ARXIV_FETCHER" search "QUERY". If the input strings (like QUERY or ARXIV_ID) contain shell metacharacters such as semicolons, backticks, or unescaped quotes, this could lead to unintended command execution. - [DYNAMIC_EXECUTION]: The workflow dynamically resolves the paths for execution scripts (
arxiv_fetch.pyandresearch_wiki.py) by reading local project files (.aris/installed-skills.txt) and files in the user's home directory ($HOME/.aris/repo). Running scripts from dynamically resolved paths introduces a dependency on the integrity of those local files and directories. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content (titles and abstracts) from the arXiv API. This content is then summarized and analyzed by the agent, creating a surface for potential injection attacks hidden within academic papers.
- Ingestion points: Academic paper abstracts and titles fetched from the
export.arxiv.orgAPI in Step 2 and Step 3. - Boundary markers: The instructions do not implement any boundary markers or "ignore instructions" delimiters when processing the retrieved abstract text.
- Capability inventory: The skill has access to the
Bash(*),Read, andWritetools, which could be exploited if an injection in a paper abstract successfully influences the agent's behavior. - Sanitization: There is no evidence of sanitization or safety filtering performed on the paper abstracts before the agent extracts "Key contributions" from them.
Audit Metadata