paper-plan
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses a Bash script to resolve the path of a helper tool (
extract_paper_style.py) at runtime. It parses local configuration files (.aris/installed-skills.txtor~/.aris/repo) usingawkto determine theARIS_REPOpath, which is then used to construct the execution path for the script. This dynamic resolution makes the skill's behavior dependent on the state of local configuration files. - [COMMAND_EXECUTION]: The skill provides a Bash block for the agent to execute when the optional
— style-refargument is used. This block interpolates the user-supplied<source>value directly into a shell command (python3 "$STYLE_HELPER" --source "<source>"). If the agent does not properly escape the<source>string, it could lead to command injection, especially sinceBash(*)is an allowed tool. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant surface for indirect prompt injection:
- Ingestion points: It reads multiple user-controlled files including
NARRATIVE_REPORT.md,STORY.md,AUTO_REVIEW.md,IDEA_REPORT.md, and various JSON experiment logs. - Boundary markers: There are no specific boundary markers or "ignore embedded instructions" warnings mentioned for these ingestion points.
- Capability inventory: The skill possesses powerful capabilities including
Bashexecution,Writeaccess to the file system, and network access viaWebFetchandWebSearch. - Sanitization: No sanitization or validation of the content within the research documents is specified before the data is processed or passed to the reviewer model (
gpt-6-astra). - [EXTERNAL_DOWNLOADS]: The
— style-reffeature allows the user to provide an HTTP(S) URL or an arXiv ID. The skill subsequently uses these external sources to guide the outline structure, with the data being fetched and processed by an external script.
Audit Metadata