javascript-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The reference guides (specifically references/tool-builder.md and references/agent-patterns.md) provide code examples that use the JavaScript eval() function to implement a calculator tool. While presented as an example, this pattern facilitates arbitrary code execution if implemented as shown without rigorous input sanitization.
  • [INDIRECT_PROMPT_INJECTION]: The SDK facilitates the creation of agents that ingest and process untrusted data from users, web search results, and file uploads, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context through agent.sendMessage inputs, appTool outputs, webSearch results, and file content processing described in SKILL.md and references/files.md.
  • Boundary markers: Documentation examples do not demonstrate the use of delimiters or isolation prompts to separate untrusted data from instructions.
  • Capability inventory: Agents built using this SDK are demonstrated with access to sensitive capabilities including shell execution (Bash tools), file system operations (fs), and network communication.
  • Sanitization: Provided examples do not include evidence of input validation or sanitization for data interpolated into agent prompts or passed to tool handlers.
  • [EXTERNAL_DOWNLOADS]: The documentation recommends the installation of an external utility skill (belt-sh/cli) via the platform's extension mechanism. Users should exercise caution when adding third-party skills that extend platform capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:24 AM
Security Audit — agent-trust-hub — javascript-sdk