langgraph

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The calculator tool in the Basic Agent Graph section uses the eval() function to evaluate string expressions. This is a highly insecure practice as it allows for the execution of arbitrary Python code if the input string is not strictly controlled or sanitized.
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection because the calculator tool processes inputs derived from the AgentState messages.
  • Ingestion points: User messages and potential outputs from the search tool are stored in the messages list within AgentState in SKILL.md.
  • Boundary markers: The example code lacks boundary markers or instructions to the LLM to ignore potentially malicious embedded content in data processed for tool calls.
  • Capability inventory: The skill possesses dynamic execution capability via the eval() call in the calculator tool.
  • Sanitization: There is no evidence of input validation, filtering, or sanitization before passing the string to the eval() function.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — langgraph