autoresearch

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions specify using the open command to automatically launch the generated dashboard in the user's default browser.\n- [EXTERNAL_DOWNLOADS]: The skill is directed to include a Content Delivery Network (CDN) reference for the Chart.js library in the generated HTML dashboard.\n- [DYNAMIC_EXECUTION]: The skill assembles an HTML file at runtime that includes data derived from the execution of other skills. This data is not sanitized before being embedded, which could lead to arbitrary JavaScript execution in the browser context if a tested skill produces malicious output.\n- [INDIRECT_PROMPT_INJECTION]: The optimization loop relies on reading and processing external skill files and their runtime outputs. This creates a surface where embedded instructions in those external files could manipulate the optimization logic or the dashboard generation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 03:29 AM