bezalel-sandbox
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides the
sandbox__exectool to run arbitrary shell commands. These operations are explicitly scoped to isolated, disposable microVMs to prevent impacts on the host operating system. - [INDIRECT_PROMPT_INJECTION]: The skill provides capabilities to read file content and command output from the sandbox, which could contain instructions from untrusted or generated code.
- Ingestion points: Command output (
stdout/stderr) fromsandbox__execand file content fromsandbox__read_file(defined in SKILL.md). - Boundary markers: Not explicitly defined in the provided tool descriptions.
- Capability inventory: The skill provides full shell execution, file system management, and lifecycle control (create/list/kill) within the sandbox scope.
- Sanitization: The platform applies output truncation to prevent context overflow, but no explicit content filtering or escaping is mentioned in the skill documentation.
Audit Metadata