autoresearch
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill design incorporates a
mission_validator_commandwhich is stored in and retrieved from a state file (.omx/state/.../autoresearch-state.json). This architecture involves the execution of shell commands that are dynamically defined in a configuration file, presenting a risk if the state file is manipulated or contains unsanitized input. - [INDIRECT_PROMPT_INJECTION]: The research loop is gated by the outputs of validators and processed research artifacts. This creates a surface where malicious instructions could be embedded in the data being researched or in the validator's feedback, potentially influencing the agent's actions in a multi-step workflow.
- Ingestion points: External research data,
mission.md, and validator result artifacts (e.g.,result.json). - Boundary markers: The documentation does not specify the use of delimiters or instructions to ignore embedded commands within the processed artifacts.
- Capability inventory: The skill possesses the capability to execute arbitrary shell commands defined in the
mission_validator_commandfield. - Sanitization: There is no evidence of sanitization or strict schema validation for the data ingested during the research and validation phases.
Audit Metadata