arxiv

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's instructions require the agent to build shell commands by directly interpolating user-provided inputs into strings, such as python3 "$ARXIV_FETCHER" search "QUERY". If the input strings (like QUERY or ARXIV_ID) contain shell metacharacters such as semicolons, backticks, or unescaped quotes, this could lead to unintended command execution.
  • [DYNAMIC_EXECUTION]: The workflow dynamically resolves the paths for execution scripts (arxiv_fetch.py and research_wiki.py) by reading local project files (.aris/installed-skills.txt) and files in the user's home directory ($HOME/.aris/repo). Running scripts from dynamically resolved paths introduces a dependency on the integrity of those local files and directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content (titles and abstracts) from the arXiv API. This content is then summarized and analyzed by the agent, creating a surface for potential injection attacks hidden within academic papers.
  • Ingestion points: Academic paper abstracts and titles fetched from the export.arxiv.org API in Step 2 and Step 3.
  • Boundary markers: The instructions do not implement any boundary markers or "ignore instructions" delimiters when processing the retrieved abstract text.
  • Capability inventory: The skill has access to the Bash(*), Read, and Write tools, which could be exploited if an injection in a paper abstract successfully influences the agent's behavior.
  • Sanitization: There is no evidence of sanitization or safety filtering performed on the paper abstracts before the agent extracts "Key contributions" from them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:49 PM
Security Audit — agent-trust-hub — arxiv