guidance

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill includes code examples that utilize the eval() function to execute logic based on strings generated by an LLM. \n
  • Evidence: In references/common-patterns.md and references/examples.md, the react_agent example implements a calculator tool using tools = {'calculator': lambda expr: eval(expr)}. The skill then executes this tool using model-generated content: result = tools[lm['action']](lm['action_input']). \n
  • Risk: Because action_input is generated by the LLM in response to potentially untrusted user input, an attacker can use prompt injection to trick the model into generating malicious Python code that will be executed with the privileges of the agent environment. \n- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting untrusted data and processing it with models that have access to executable tools, creating an attack surface for indirect prompt injection. \n
  • Ingestion points: The react_agent and extract_entities functions (found in SKILL.md and reference files) accept arbitrary question and text strings as inputs. \n
  • Boundary markers: Example prompts lack robust delimiters or instructions to prevent the model from interpreting commands embedded within the provided text. \n
  • Capability inventory: The agent examples include the ability to execute code via the eval()-based calculator tool. \n
  • Sanitization: The examples do not demonstrate any sanitization, input validation, or sandboxing of the strings before they are passed to the eval() function.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — guidance