langgraph
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides a code example for a
calculatortool (inSKILL.md) that uses theeval()function to process input strings. Usingeval()allows for the execution of arbitrary Python code, which presents a significant security risk if the input (theexpressionargument) is derived from untrusted sources, such as model-generated content or user prompts. - [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for processing external data without sufficient security controls.
- Ingestion points: The
app.invoke()method in the 'Basic Agent Graph' example (inSKILL.md) accepts amessageslist which typically contains untrusted user input. - Boundary markers: There are no delimiters or instructions provided to the agent to treat the
messagescontent as data rather than instructions. - Capability inventory: The defined nodes include a
searchtool (network/information access) and acalculatortool (eval()based code execution). - Sanitization: The skill lacks any evidence of input validation, output filtering, or sanitization logic to prevent embedded instructions in user messages from hijacking the agent's control flow.
Audit Metadata