auto-paper-improvement-loop

Fail

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill reads the file ~/.claude/feishu.json. This file is used to store sensitive API keys or tokens for Feishu notifications, and accessing credential files in the home directory is a high-severity security concern.
  • [DYNAMIC_EXECUTION]: The skill resolves the path for the extract_paper_style.py script using values from ~/.aris/repo or .aris/installed-skills.txt. Executing code from a path resolved at runtime from local configuration files allows for potential arbitrary code execution if those files are manipulated.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted paper content (LaTeX, PDF) and external style references (URLs, arXiv IDs) which are then processed by a high-capability LLM (gpt-6-astra). The agent implements filesystem changes and shell commands based on the LLM's output without adequate sanitization or boundary markers.
  • Ingestion points: LaTeX source files in paper/sections/, compiled paper/main.pdf, and external --style-ref sources.
  • Boundary markers: Absent. There are no instructions to the model to ignore malicious directives within the analyzed documents.
  • Capability inventory: The agent utilizes Bash, Write, Edit, and latexmk, which provide broad access to the filesystem and system execution.
  • Sanitization: No validation or sanitization is performed on the content extracted from the input papers or references.
  • [COMMAND_EXECUTION]: The skill uses various shell commands, including latexmk, python3, grep, awk, and jq, to compile papers and process metadata.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 29, 2026, 02:43 PM
Security Audit — agent-trust-hub — auto-paper-improvement-loop