deepagents-implementation
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements an
executetool that allows agents to run arbitrary shell commands. This capability is intended for use with theFilesystemBackendand is a core part of the developer-focused toolset. - [EXTERNAL_DOWNLOADS]: The documentation describes integration with Model Context Protocol (MCP) servers, which involves executing remote packages such as
@modelcontextprotocol/server-filesystemand@modelcontextprotocol/server-githubvia thenpxcommand. - [INDIRECT_PROMPT_INJECTION]: The skill creates a significant surface for indirect prompt injection by processing untrusted data from users and external tool outputs while maintaining high-privilege capabilities.
- Ingestion points: User messages passed to
invokeorstreammethods, and data retrieved through theweb_searchandread_filetools. - Boundary markers: The provided system prompt examples do not include explicit instructions or delimiters to isolate untrusted data from the agent's core instruction set.
- Capability inventory: Includes shell command execution (
execute), filesystem modification (write_file,edit_file), and the ability to launch subagents via thetasktool. - Sanitization: The skill documentation does not outline specific sanitization, validation, or filtering logic for external content beyond basic filesystem path requirements.
- [DATA_EXFILTRATION]: The availability of filesystem read tools (
read_file,ls,grep) alongside network-capable tools (web_search) creates a potential path for data exfiltration if the agent is manipulated by a malicious prompt.
Audit Metadata