autonomous-agent-patterns
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
MCPAgentclass inSKILL.mdillustrates a pattern where the agent generates Python code via an LLM and writes it directly to a local file (server.py), which is then dynamically loaded into the execution environment. This "hot-reload" mechanism for unverified, model-generated code lacks human-in-the-loop validation and represents a significant risk for the execution of malicious logic. - [INDIRECT_PROMPT_INJECTION]: The skill implement patterns that are vulnerable to indirect prompt injection attacks.
- Ingestion points: The
ContextManager.add_urlandBrowserTool.get_page_contentmethods inSKILL.mdingest arbitrary text from external web pages. - Boundary markers: The
format_for_promptmethod interpolates this content into the prompt without using secure delimiters or instructions to the LLM to ignore embedded commands. - Capability inventory: The agent's documented capabilities include file system modification (
EditFileTool), shell command execution (SandboxedExecution), and network requests. - Sanitization: The skill does not perform any validation or sanitization of the external content before it is added to the agent's context.
- [COMMAND_EXECUTION]: The
SandboxedExecutionpattern usessubprocess.runwithshell=True. While it includes a validation step usingshlex, executing commands through a shell remains a dangerous practice that increases the surface area for command injection via shell metacharacters.
Audit Metadata