autonomous-agent-patterns

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The MCPAgent pattern in SKILL.md describes an agent generating Python code based on descriptions, saving it to disk, and executing it. This demonstrates a high-risk dynamic code generation and execution flow.
  • [COMMAND_EXECUTION]: The SandboxedExecution and CheckpointManager patterns in SKILL.md utilize subprocess.run with shell=True and subprocess.getoutput to execute shell commands, which are patterns prone to command injection if used with untrusted input.
  • [EXTERNAL_DOWNLOADS]: The ContextManager pattern in SKILL.md provides code to fetch data from external URLs via requests.get.
  • [DATA_EXFILTRATION]: Patterns for comprehensive file system reads (ReadFileTool) and environment variable access (os.environ) are documented in SKILL.md, presenting risks of sensitive data exposure if implemented without strict access controls.
  • [PROMPT_INJECTION]: The ContextManager pattern creates an indirect prompt injection surface by ingesting external content without proper protection. Evidence: (1) Ingestion point: ContextManager.add_url in SKILL.md. (2) Boundary markers: None used in the prompt formatting logic. (3) Capability inventory: Patterns for run_command and write_file are provided in the same context. (4) Sanitization: No sanitization or validation of the ingested content is demonstrated.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — autonomous-agent-patterns