code-interpreter
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill allows execution of arbitrary shell commands through the
execute_commandtool. This includes environment inspection, system utility usage, and software installation. - [DYNAMIC_EXECUTION]: The skill is designed for the runtime execution of Python, JavaScript, and TypeScript code, enabling prototyping, debugging, and data processing within a persistent workspace.
- [EXTERNAL_DOWNLOADS]: The environment supports fetching external resources via tools like
curland Python libraries such asrequests. It also allows the installation of third-party packages from registries like PyPI. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it is designed to ingest and process data from external sources (web scraping, API calls, and user-uploaded files) that may contain hidden instructions.
- Ingestion points: User-provided file attachments located in
/mnt/workspace/inputsand external data fetched via network operations (requests,httpx). - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded in processed data.
- Capability inventory: The skill provides comprehensive system access including arbitrary code execution, shell command execution, and file system modification.
- Sanitization: There are no explicit mechanisms or instructions for sanitizing, escaping, or validating external content before it is processed by the agent.
Audit Metadata