autoresearch-verify

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because it instructs the agent to read repository content to determine the script's logic.
  • Ingestion points: The agent reads the target repository and asks the human for info (Objective, Primary metric, Budget, etc.) to generate the verify.py script.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the repository files are provided.
  • Capability inventory: The agent has the capability to write files to the repository root and execute shell commands to run the generated Python script.
  • Sanitization: There is no explicit requirement to sanitize or validate strings gathered from the repository before interpolating them into the generated code.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the generated code at runtime (Category 10).
  • Execution pattern: The 'Verification before declaring complete' section explicitly commands the agent to run python verify.py --mode light and python verify.py --mode heavy to ensure they work. If the generation process was compromised by indirect injection, this results in the execution of attacker-influenced code.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 09:21 PM
Security Audit — agent-trust-hub — autoresearch-verify