bezalel-sandbox

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides the sandbox__exec tool to run arbitrary shell commands. These operations are explicitly scoped to isolated, disposable microVMs to prevent impacts on the host operating system.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides capabilities to read file content and command output from the sandbox, which could contain instructions from untrusted or generated code.
  • Ingestion points: Command output (stdout/stderr) from sandbox__exec and file content from sandbox__read_file (defined in SKILL.md).
  • Boundary markers: Not explicitly defined in the provided tool descriptions.
  • Capability inventory: The skill provides full shell execution, file system management, and lifecycle control (create/list/kill) within the sandbox scope.
  • Sanitization: The platform applies output truncation to prevent context overflow, but no explicit content filtering or escaping is mentioned in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — bezalel-sandbox