skills/wanshuiyin/auto-claude-code-research-in-sleep/auto-paper-improvement-loop/Gen Agent Trust Hub
auto-paper-improvement-loop
Fail
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill reads the file
~/.claude/feishu.json. This file is used to store sensitive API keys or tokens for Feishu notifications, and accessing credential files in the home directory is a high-severity security concern. - [DYNAMIC_EXECUTION]: The skill resolves the path for the
extract_paper_style.pyscript using values from~/.aris/repoor.aris/installed-skills.txt. Executing code from a path resolved at runtime from local configuration files allows for potential arbitrary code execution if those files are manipulated. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted paper content (LaTeX, PDF) and external style references (URLs, arXiv IDs) which are then processed by a high-capability LLM (
gpt-6-astra). The agent implements filesystem changes and shell commands based on the LLM's output without adequate sanitization or boundary markers. - Ingestion points: LaTeX source files in
paper/sections/, compiledpaper/main.pdf, and external--style-refsources. - Boundary markers: Absent. There are no instructions to the model to ignore malicious directives within the analyzed documents.
- Capability inventory: The agent utilizes
Bash,Write,Edit, andlatexmk, which provide broad access to the filesystem and system execution. - Sanitization: No validation or sanitization is performed on the content extracted from the input papers or references.
- [COMMAND_EXECUTION]: The skill uses various shell commands, including
latexmk,python3,grep,awk, andjq, to compile papers and process metadata.
Recommendations
- AI detected serious security threats
Audit Metadata