result-to-claim
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill executes Python scripts (
evidence_check.py,research_wiki.py) from paths computed at runtime. It attempts to resolve these scripts from multiple locations, including a path stored in the user's home directory (~/.aris/repo) or a project-level file (.aris/installed-skills.txt). If these configuration files are manipulated, an attacker could direct the skill to execute arbitrary Python code. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources, including experiment logs, W&B API outputs, and project documentation. This data is interpolated into a prompt for an LLM (Step 2: Codex Judgment) without explicit sanitization or strict boundary markers.
- Ingestion points: experiment-description-or-wandb-run arguments,
EXPERIMENT_LOG.md,EXPERIMENT_TRACKER.md, and remote server logs. - Boundary markers: The prompt uses section headers like
RESULT-TO-CLAIM EVALUATIONandResults:, but these are susceptible to override by malicious content within the results. - Capability inventory: The skill has access to Bash execution, file writing/editing, and SSH commands.
- Sanitization: No sanitization or escaping of external content is specified before interpolation.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute system commands such as
git,awk,ssh, andpython3. Specifically, it instructs the agent to runssh server "tail -100 /path/to/training.log", which involves connecting to and executing commands on remote infrastructure based on potentially untrusted path variables.
Audit Metadata