autoresearch

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill design incorporates a mission_validator_command which is stored in and retrieved from a state file (.omx/state/.../autoresearch-state.json). This architecture involves the execution of shell commands that are dynamically defined in a configuration file, presenting a risk if the state file is manipulated or contains unsanitized input.
  • [INDIRECT_PROMPT_INJECTION]: The research loop is gated by the outputs of validators and processed research artifacts. This creates a surface where malicious instructions could be embedded in the data being researched or in the validator's feedback, potentially influencing the agent's actions in a multi-step workflow.
  • Ingestion points: External research data, mission.md, and validator result artifacts (e.g., result.json).
  • Boundary markers: The documentation does not specify the use of delimiters or instructions to ignore embedded commands within the processed artifacts.
  • Capability inventory: The skill possesses the capability to execute arbitrary shell commands defined in the mission_validator_command field.
  • Sanitization: There is no evidence of sanitization or strict schema validation for the data ingested during the research and validation phases.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — autoresearch