dynamic-code-compiler
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: CRITICALDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The function 'compile_source' in 'process.py' utilizes the 'compile()' built-in with 'exec' mode to transform the 'user_source' input into a code object. This primitive allows for the generation of executable code from arbitrary strings, posing a major risk of arbitrary code execution.
- [INDIRECT_PROMPT_INJECTION]: The skill accepts source code as input without sanitization, providing a direct injection surface.
- Ingestion points: 'user_source' parameter in 'process.py'.
- Boundary markers: None identified.
- Capability inventory: Python 'compile()' function in 'process.py'.
- Sanitization: No filtering or validation is performed on the input string.
Recommendations
- AI detected serious security threats
Audit Metadata