julia-vibe-coding

Warn

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Instructs the user to clone a repository from an external source (github.com/aplavin/julia-mcp) to obtain the necessary server scripts for the skill to function.
  • [REMOTE_CODE_EXECUTION]: The installation process involves registering an external script to be executed by the agent platform (uv run ... python server.py). This allows third-party code from an unverified repository to run within the agent's environment.
  • [COMMAND_EXECUTION]: The skill's core functionality relies on the julia_eval tool, which executes arbitrary Julia code. This tool has extensive system access, including the ability to run shell commands, manipulate files, and access the network.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to include and execute the contents of local .jl files. If an attacker can influence the content of these files, they can execute malicious code through the agent.
  • Ingestion points: Julia files in the scripts/ directory are loaded and executed via the include() function within a julia_eval call in SKILL.md.
  • Boundary markers: There are no mechanisms or instructions provided to isolate the script content or prevent the execution of embedded malicious instructions.
  • Capability inventory: The julia_eval tool provides access to a persistent Julia environment capable of subprocess execution, file I/O, and network connectivity.
  • Sanitization: No validation, escaping, or sanitization is performed on the script content before it is passed to the Julia interpreter.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 8, 2026, 12:14 PM
Security Audit — agent-trust-hub — julia-vibe-coding