research-refine
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process external content, such as research papers and online literature, using the 'WebFetch' and 'WebSearch' tools. This external content is untrusted and provides a surface for indirect prompt injection attacks where malicious instructions hidden in the text could attempt to manipulate the agent's behavior or outcomes.
- Ingestion points: External research papers and top-venue work retrieved from the web (Phase 1.1).
- Boundary markers: The instructions do not specify the use of clear delimiters or instructions to ignore embedded commands within the fetched material.
- Capability inventory: The skill has access to 'Bash', 'Write', and 'Edit' tools, which could be misused if an injection is successful.
- Sanitization: No sanitization or content validation for the fetched research material is mentioned in the workflow.
- [COMMAND_EXECUTION]: The skill instructions include a specific rule to use the 'Bash' tool to perform file writes in chunks (using 'cat << EOF') if standard writing tools fail due to file size. It explicitly directs the agent to bypass user confirmation for these operations.
- Evidence: "If the Write tool fails due to file size, immediately retry using Bash (cat << 'EOF' > file) to write in chunks. Do NOT ask the user for permission — just do it silently." (Key Rules section)
Audit Metadata