adk
Fail
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
calculatefunction defined inSKILL.mduses the Pythoneval()function to process theexpressionargument. This is a dangerous pattern that permits the execution of arbitrary Python code (e.g., system commands or file access) if the input is not strictly controlled and sanitized. - [REMOTE_CODE_EXECUTION]: Because the
calculatetool is intended for use by an AI agent that handles potentially untrusted user input, the use ofeval()provides a mechanism for Remote Code Execution (RCE) via prompt injection. - [EXTERNAL_DOWNLOADS]: The skill documentation provides instructions to install the
google-adklibrary across various package managers including pip, npm, and go. These resources originate from a well-known service (Google) and are considered safe. - [INDIRECT_PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection as it ingests untrusted data that flows into a tool with arbitrary code execution capabilities.
- Ingestion points: User messages are ingested via the
Runnerandnew_messagecontent inSKILL.md. - Boundary markers: None. The agent instructions and prompt templates in
SKILL.md(e.g.,{user_name}) lack delimiters or instructions to treat injected variables as non-executable data. - Capability inventory: The skill provides a calculation tool in
SKILL.mdthat leverageseval()for code execution. - Sanitization: There is no input validation or sanitization implemented for the
expressionstring before it is passed to the Python interpreter.
Recommendations
- AI detected serious security threats
Audit Metadata