guidance
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill includes code examples that utilize the
eval()function to execute logic based on strings generated by an LLM. \n - Evidence: In
references/common-patterns.mdandreferences/examples.md, thereact_agentexample implements a calculator tool usingtools = {'calculator': lambda expr: eval(expr)}. The skill then executes this tool using model-generated content:result = tools[lm['action']](lm['action_input']). \n - Risk: Because
action_inputis generated by the LLM in response to potentially untrusted user input, an attacker can use prompt injection to trick the model into generating malicious Python code that will be executed with the privileges of the agent environment. \n- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting untrusted data and processing it with models that have access to executable tools, creating an attack surface for indirect prompt injection. \n - Ingestion points: The
react_agentandextract_entitiesfunctions (found inSKILL.mdand reference files) accept arbitraryquestionandtextstrings as inputs. \n - Boundary markers: Example prompts lack robust delimiters or instructions to prevent the model from interpreting commands embedded within the provided text. \n
- Capability inventory: The agent examples include the ability to execute code via the
eval()-based calculator tool. \n - Sanitization: The examples do not demonstrate any sanitization, input validation, or sandboxing of the strings before they are passed to the
eval()function.
Recommendations
- AI detected serious security threats
Audit Metadata