javascript-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The reference guides (specifically
references/tool-builder.mdandreferences/agent-patterns.md) provide code examples that use the JavaScripteval()function to implement a calculator tool. While presented as an example, this pattern facilitates arbitrary code execution if implemented as shown without rigorous input sanitization. - [INDIRECT_PROMPT_INJECTION]: The SDK facilitates the creation of agents that ingest and process untrusted data from users, web search results, and file uploads, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through
agent.sendMessageinputs,appTooloutputs,webSearchresults, and file content processing described inSKILL.mdandreferences/files.md. - Boundary markers: Documentation examples do not demonstrate the use of delimiters or isolation prompts to separate untrusted data from instructions.
- Capability inventory: Agents built using this SDK are demonstrated with access to sensitive capabilities including shell execution (
Bashtools), file system operations (fs), and network communication. - Sanitization: Provided examples do not include evidence of input validation or sanitization for data interpolated into agent prompts or passed to tool handlers.
- [EXTERNAL_DOWNLOADS]: The documentation recommends the installation of an external utility skill (
belt-sh/cli) via the platform's extension mechanism. Users should exercise caution when adding third-party skills that extend platform capabilities.
Audit Metadata