research-wiki
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses a complex Bash resolution logic to locate and execute a Python helper script (
research_wiki.py). It searches across several potential paths, including.aris/tools/,tools/, and paths specified in~/.aris/repo, before executing the script withpython3. This dynamic loading from computed paths is a significant risk as it allows the execution of arbitrary local scripts whose location is determined at runtime based on environment variables or configuration files. - [COMMAND_EXECUTION]: The skill requests and utilizes the
Bash(*)tool to perform system-level operations such as repository navigation, directory initialization, and executing Python subcommands. It directly interpolates subcommands and arguments into shell execution strings, which are then passed to the resolved helper scripts. - [INDIRECT_PROMPT_INJECTION]: The
ingestandsyncsubcommands fetch paper metadata and abstracts from the external arXiv Atom API. Maliciously crafted data from these sources could be used to inject instructions that might influence the agent's behavior during subsequent wiki queries or ideation tasks. - Ingestion points: Fetches research paper metadata and abstracts from the arXiv Atom API through the
ingest_paperfunction. - Boundary markers: The skill mentions a "capture hygiene" process using a
capture_filter.pyscript to screen for "operational noise" and "anti-self-poisoning," but does not define explicit delimiters or instructions to ignore embedded commands in ingested text. - Capability inventory: Broad shell access (
Bash), file system modification (Write,Edit), and network access (WebFetch,WebSearch). - Sanitization: Relies on an external
capture_filter.pyscript for screening, which is itself dynamically resolved from the project directory and is not part of the skill's static instructions.
Audit Metadata