code-interpreter

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill allows execution of arbitrary shell commands through the execute_command tool. This includes environment inspection, system utility usage, and software installation.
  • [DYNAMIC_EXECUTION]: The skill is designed for the runtime execution of Python, JavaScript, and TypeScript code, enabling prototyping, debugging, and data processing within a persistent workspace.
  • [EXTERNAL_DOWNLOADS]: The environment supports fetching external resources via tools like curl and Python libraries such as requests. It also allows the installation of third-party packages from registries like PyPI.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it is designed to ingest and process data from external sources (web scraping, API calls, and user-uploaded files) that may contain hidden instructions.
  • Ingestion points: User-provided file attachments located in /mnt/workspace/inputs and external data fetched via network operations (requests, httpx).
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded in processed data.
  • Capability inventory: The skill provides comprehensive system access including arbitrary code execution, shell command execution, and file system modification.
  • Sanitization: There are no explicit mechanisms or instructions for sanitizing, escaping, or validating external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 12:35 AM