skill-autoresearch

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform repository-local tasks such as executing dry-run benchmarks, validation scripts, and file management operations.\n- [DATA_EXFILTRATION]: The skill includes WebFetch in its allowed-tools and references an external GitHub repository in its metadata for documentation and upstream synchronization purposes.\n- [SAFE]: The instructions do not contain prompt injection, obfuscation, or persistence mechanisms. The workflow focuses on disciplined engineering practices including freezing evaluators and logging experiments.\n- [SAFE]: The skill ingests untrusted local artifacts (SKILL.md, SOPs) as ingestion points. While boundary markers and sanitization are absent, the capability inventory (Bash, Write, Read) is managed within a repo-local context under an iterative benchmark regime.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 04:31 AM