deepagents-implementation

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements an execute tool that allows agents to run arbitrary shell commands. This capability is intended for use with the FilesystemBackend and is a core part of the developer-focused toolset.
  • [EXTERNAL_DOWNLOADS]: The documentation describes integration with Model Context Protocol (MCP) servers, which involves executing remote packages such as @modelcontextprotocol/server-filesystem and @modelcontextprotocol/server-github via the npx command.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a significant surface for indirect prompt injection by processing untrusted data from users and external tool outputs while maintaining high-privilege capabilities.
  • Ingestion points: User messages passed to invoke or stream methods, and data retrieved through the web_search and read_file tools.
  • Boundary markers: The provided system prompt examples do not include explicit instructions or delimiters to isolate untrusted data from the agent's core instruction set.
  • Capability inventory: Includes shell command execution (execute), filesystem modification (write_file, edit_file), and the ability to launch subagents via the task tool.
  • Sanitization: The skill documentation does not outline specific sanitization, validation, or filtering logic for external content beyond basic filesystem path requirements.
  • [DATA_EXFILTRATION]: The availability of filesystem read tools (read_file, ls, grep) alongside network-capable tools (web_search) creates a potential path for data exfiltration if the agent is manipulated by a malicious prompt.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 04:07 PM
Security Audit — agent-trust-hub — deepagents-implementation