langchain

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The 'Calculator' tool example in SKILL.md and references/agents.md uses the eval() function to process input strings. This allows for arbitrary Python code execution if the agent passes unvalidated or malicious strings to the tool.
  • [DYNAMIC_EXECUTION]: In references/integration.md, the documentation for loading FAISS vector stores explicitly sets allow_dangerous_deserialization=True. This enables the Python pickle module to load data, which presents a significant risk of arbitrary code execution if the agent is tricked into loading a malicious index file from an external source.
  • [COMMAND_EXECUTION]: The integration guide in references/integration.md demonstrates the use of ShellTool and PythonREPLTool. These tools grant the agent the capability to execute arbitrary system commands and Python scripts, which could be exploited to perform unauthorized actions on the host environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes RAG (Retrieval-Augmented Generation) pipelines that ingest data from untrusted external sources.
  • Ingestion points: Data is loaded from web pages, PDFs, and GitHub repositories using WebBaseLoader, PyPDFLoader, and GithubFileLoader as shown in SKILL.md and references/rag.md.
  • Boundary markers: While prompt templates are provided, they do not include robust instructions to ignore potentially malicious instructions embedded within retrieved documents.
  • Capability inventory: The agent context includes powerful capabilities such as shell access (ShellTool), Python execution (PythonREPLTool), and database manipulation tools (SQLDatabase).
  • Sanitization: The provided examples lack comprehensive logic for sanitizing or validating retrieved content before it is interpolated into LLM prompts.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and content from well-known external sources including Python's official documentation at docs.python.org and NumPy's documentation at docs.numpy.org.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — langchain