autonomous-agent-patterns

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The MCPAgent.create_tool pattern describes a workflow where the agent generates Python code for a new tool via an LLM, writes it to the local filesystem, and then dynamically loads and executes it using the MCP framework.\n- [COMMAND_EXECUTION]: The SandboxedExecution class uses subprocess.run with shell=True to execute terminal commands. Although it includes a basic whitelist and path validation, using a shell for execution increases the risk of command injection if validation logic is insufficient.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external URLs and files into the agent's prompt context. Ingestion points: Found in ContextManager.add_url and BrowserTool.get_page_content. Boundary markers: Uses markdown headers and code blocks as delimiters in ContextManager.format_for_prompt. Capability inventory: The agent patterns include shell access (subprocess.run), file system access (open), network requests (requests.get), and browser automation (playwright). Sanitization: No explicit sanitization or filtering of the ingested external content is performed before injection.\n- [EXTERNAL_DOWNLOADS]: The ContextManager.add_url method uses the requests library to fetch content from user-specified or external URLs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — autonomous-agent-patterns