paper-plan

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses a Bash script to resolve the path of a helper tool (extract_paper_style.py) at runtime. It parses local configuration files (.aris/installed-skills.txt or ~/.aris/repo) using awk to determine the ARIS_REPO path, which is then used to construct the execution path for the script. This dynamic resolution makes the skill's behavior dependent on the state of local configuration files.
  • [COMMAND_EXECUTION]: The skill provides a Bash block for the agent to execute when the optional — style-ref argument is used. This block interpolates the user-supplied <source> value directly into a shell command (python3 "$STYLE_HELPER" --source "<source>"). If the agent does not properly escape the <source> string, it could lead to command injection, especially since Bash(*) is an allowed tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant surface for indirect prompt injection:
  • Ingestion points: It reads multiple user-controlled files including NARRATIVE_REPORT.md, STORY.md, AUTO_REVIEW.md, IDEA_REPORT.md, and various JSON experiment logs.
  • Boundary markers: There are no specific boundary markers or "ignore embedded instructions" warnings mentioned for these ingestion points.
  • Capability inventory: The skill possesses powerful capabilities including Bash execution, Write access to the file system, and network access via WebFetch and WebSearch.
  • Sanitization: No sanitization or validation of the content within the research documents is specified before the data is processed or passed to the reviewer model (gpt-6-astra).
  • [EXTERNAL_DOWNLOADS]: The — style-ref feature allows the user to provide an HTTP(S) URL or an arXiv ID. The skill subsequently uses these external sources to guide the outline structure, with the data being fetched and processed by an external script.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 02:42 PM
Security Audit — agent-trust-hub — paper-plan