langgraph
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
calculatortool in theBasic Agent Graphsection uses theeval()function to evaluate string expressions. This is a highly insecure practice as it allows for the execution of arbitrary Python code if the input string is not strictly controlled or sanitized. - [INDIRECT_PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection because the
calculatortool processes inputs derived from theAgentStatemessages. - Ingestion points: User messages and potential outputs from the
searchtool are stored in themessageslist withinAgentStateinSKILL.md. - Boundary markers: The example code lacks boundary markers or instructions to the LLM to ignore potentially malicious embedded content in data processed for tool calls.
- Capability inventory: The skill possesses dynamic execution capability via the
eval()call in thecalculatortool. - Sanitization: There is no evidence of input validation, filtering, or sanitization before passing the string to the
eval()function.
Audit Metadata