autonomous-agent-patterns
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The MCPAgent pattern in SKILL.md describes an agent generating Python code based on descriptions, saving it to disk, and executing it. This demonstrates a high-risk dynamic code generation and execution flow.
- [COMMAND_EXECUTION]: The SandboxedExecution and CheckpointManager patterns in SKILL.md utilize subprocess.run with shell=True and subprocess.getoutput to execute shell commands, which are patterns prone to command injection if used with untrusted input.
- [EXTERNAL_DOWNLOADS]: The ContextManager pattern in SKILL.md provides code to fetch data from external URLs via requests.get.
- [DATA_EXFILTRATION]: Patterns for comprehensive file system reads (ReadFileTool) and environment variable access (os.environ) are documented in SKILL.md, presenting risks of sensitive data exposure if implemented without strict access controls.
- [PROMPT_INJECTION]: The ContextManager pattern creates an indirect prompt injection surface by ingesting external content without proper protection. Evidence: (1) Ingestion point:
ContextManager.add_urlin SKILL.md. (2) Boundary markers: None used in the prompt formatting logic. (3) Capability inventory: Patterns forrun_commandandwrite_fileare provided in the same context. (4) Sanitization: No sanitization or validation of the ingested content is demonstrated.
Audit Metadata