meta-apply
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
Bashto execute shell commands (e.g.,python3,cat) with arguments like$TARGET,$AUTHOR, and$JURY_THREAD_IDderived from an externalmanifest.jsonlfile. Without explicit sanitization of these variables before interpolation into shell commands, an attacker who compromises the producer skill could achieve arbitrary command execution during the landing process.\n- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to malicious instructions embedded in staged patches. 1. Ingestion points: staged.difffiles and themanifest.jsonlin the.aris/meta/pending/directory. 2. Boundary markers: The skill uses fresh codex threads and 'paths-only' context for the review jury, but lacks explicit data delimiters or "ignore instructions" headers. 3. Capability inventory: The skill has the power toWriteandEditthe skill corpus and executeBashcommands. 4. Sanitization: There is no evidence of filtering or escaping patch content before review.\n- [DYNAMIC_EXECUTION]: The skill resolves theprovenance.pyutility through a multi-layer search chain involving relative paths (.aris/tools/) and user-specific directories (~/.aris/repo). This dynamic path resolution introduces a risk of script hijacking if an attacker gains write access to any of the searched locations.\n- [PRIVILEGE_ESCALATION]: The skill is explicitly designed to perform self-modification of the agent's corpus, intentionally bypassing standard write protections likecorpus_write_guard. While it incorporates verification steps, a failure in the jury logic or the human-in-the-loop review could lead to the landing of unauthorized code that permanently alters the agent's behavior.
Audit Metadata