autoresearch-program
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to generate a
program.mdfile that includes explicit instructions for an agent to operate autonomously and indefinitely. Specifically, the 'NEVER STOP' section inprogram.template.mddirects the agent to 'NOT pause to ask the human if you should continue' and to work while the human is away or asleep, which effectively attempts to bypass standard human-in-the-loop safety constraints. - [COMMAND_EXECUTION]: The instructions in
SKILL.mdrequire the agent to execute shell commands (e.g.,python verify.py) found within the repository to confirm they work before finalizing the program. This allows for the execution of arbitrary code defined in the repository's files. - [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface by performing literal string replacement of untrusted data into a prompt template (
program.template.md). - Ingestion points: User-supplied strings for placeholders and file paths/metadata from the repository.
- Boundary markers: Absent; the template uses double-curly-brace placeholders that are replaced by raw text without delimiters to separate instructions from data.
- Capability inventory: The skill possesses the ability to write files (
program.md), modify configuration (.gitignore), and execute shell commands (python verify.py). - Sanitization: Absent; there is no validation or escaping of the content substituted into
{{ACCEPTANCE_RULE}}or{{MUTABLE_SCOPE}}, allowing potentially malicious instructions in those fields to influence the generated agent directive. - [DATA_EXPOSURE]: The skill gathers information about the repository's structure and scope (e.g., mutable/immutable files) and bakes this information into a persistent file (
program.md), which could expose sensitive path structures if the generated file is shared.
Audit Metadata