dynamic-code-compiler

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: CRITICALDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The function 'compile_source' in 'process.py' utilizes the 'compile()' built-in with 'exec' mode to transform the 'user_source' input into a code object. This primitive allows for the generation of executable code from arbitrary strings, posing a major risk of arbitrary code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts source code as input without sanitization, providing a direct injection surface.
  • Ingestion points: 'user_source' parameter in 'process.py'.
  • Boundary markers: None identified.
  • Capability inventory: Python 'compile()' function in 'process.py'.
  • Sanitization: No filtering or validation is performed on the input string.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 9, 2026, 11:41 AM
Security Audit — agent-trust-hub — dynamic-code-compiler