integrity-forensics
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones the
Anti-Autoresearchrepository from GitHub (https://github.com/wanshuiyin/Anti-Autoresearch.git). The process uses a hardcoded SHA-1 commit hash (b47af6f983b38347b6d2110379e266400597cf66) to pin the version and ensure the integrity of the downloaded content. - [REMOTE_CODE_EXECUTION]: During the bootstrap phase, the skill executes a Python script (
eval/run_eval.py) located within the cloned repository. Since the repository is SHA-pinned and originates from the skill's own vendor, this is a controlled execution of remote code. - [DYNAMIC_EXECUTION]: The skill resolves and executes a helper script named
forensics_gate.pyby searching through a 'canonical chain' of directories:.aris/tools/,tools/, and$ARIS_REPO/tools/. Loading executable scripts from variable or relative paths liketools/can allow for script hijacking if an attacker can place a malicious file in the search path. - [COMMAND_EXECUTION]: The skill performs multiple shell operations to manage the tool environment, including
mkdir,git clone,git checkout,git reset, andgit clean. These commands are used to ensure the working copy is pristine and matches the expected version. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to "Open and follow" another
SKILL.mdfile located inside the downloaded repository ($CLONE_DIR/workflows/anti-autoresearch/SKILL.md). This represents a chain-loading of instructions from an external source. - Ingestion points: The agent is directed to read and follow the instructions contained in the cloned repository's markdown file.
- Boundary markers: There are no explicit markers or warnings to ignore malicious instructions within the delegated content.
- Capability inventory: The delegated instructions can leverage the same tools allowed for the launcher, including
Bash(*),Read, andWriteaccess. - Sanitization: The integrity of the instructions is protected by the SHA-pinning of the repository commit.
Audit Metadata