autonomous-agent-patterns
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The
MCPAgent.create_toolpattern describes a workflow where the agent generates Python code for a new tool via an LLM, writes it to the local filesystem, and then dynamically loads and executes it using the MCP framework.\n- [COMMAND_EXECUTION]: TheSandboxedExecutionclass usessubprocess.runwithshell=Trueto execute terminal commands. Although it includes a basic whitelist and path validation, using a shell for execution increases the risk of command injection if validation logic is insufficient.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external URLs and files into the agent's prompt context. Ingestion points: Found inContextManager.add_urlandBrowserTool.get_page_content. Boundary markers: Uses markdown headers and code blocks as delimiters inContextManager.format_for_prompt. Capability inventory: The agent patterns include shell access (subprocess.run), file system access (open), network requests (requests.get), and browser automation (playwright). Sanitization: No explicit sanitization or filtering of the ingested external content is performed before injection.\n- [EXTERNAL_DOWNLOADS]: TheContextManager.add_urlmethod uses therequestslibrary to fetch content from user-specified or external URLs.
Audit Metadata