result-to-claim

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill executes Python scripts (evidence_check.py, research_wiki.py) from paths computed at runtime. It attempts to resolve these scripts from multiple locations, including a path stored in the user's home directory (~/.aris/repo) or a project-level file (.aris/installed-skills.txt). If these configuration files are manipulated, an attacker could direct the skill to execute arbitrary Python code.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources, including experiment logs, W&B API outputs, and project documentation. This data is interpolated into a prompt for an LLM (Step 2: Codex Judgment) without explicit sanitization or strict boundary markers.
  • Ingestion points: experiment-description-or-wandb-run arguments, EXPERIMENT_LOG.md, EXPERIMENT_TRACKER.md, and remote server logs.
  • Boundary markers: The prompt uses section headers like RESULT-TO-CLAIM EVALUATION and Results:, but these are susceptible to override by malicious content within the results.
  • Capability inventory: The skill has access to Bash execution, file writing/editing, and SSH commands.
  • Sanitization: No sanitization or escaping of external content is specified before interpolation.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute system commands such as git, awk, ssh, and python3. Specifically, it instructs the agent to run ssh server "tail -100 /path/to/training.log", which involves connecting to and executing commands on remote infrastructure based on potentially untrusted path variables.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 06:51 PM
Security Audit — agent-trust-hub — result-to-claim