langchain
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The 'Calculator' tool example in
SKILL.mdandreferences/agents.mduses theeval()function to process input strings. This allows for arbitrary Python code execution if the agent passes unvalidated or malicious strings to the tool. - [DYNAMIC_EXECUTION]: In
references/integration.md, the documentation for loading FAISS vector stores explicitly setsallow_dangerous_deserialization=True. This enables the Pythonpicklemodule to load data, which presents a significant risk of arbitrary code execution if the agent is tricked into loading a malicious index file from an external source. - [COMMAND_EXECUTION]: The integration guide in
references/integration.mddemonstrates the use ofShellToolandPythonREPLTool. These tools grant the agent the capability to execute arbitrary system commands and Python scripts, which could be exploited to perform unauthorized actions on the host environment. - [INDIRECT_PROMPT_INJECTION]: The skill describes RAG (Retrieval-Augmented Generation) pipelines that ingest data from untrusted external sources.
- Ingestion points: Data is loaded from web pages, PDFs, and GitHub repositories using
WebBaseLoader,PyPDFLoader, andGithubFileLoaderas shown inSKILL.mdandreferences/rag.md. - Boundary markers: While prompt templates are provided, they do not include robust instructions to ignore potentially malicious instructions embedded within retrieved documents.
- Capability inventory: The agent context includes powerful capabilities such as shell access (
ShellTool), Python execution (PythonREPLTool), and database manipulation tools (SQLDatabase). - Sanitization: The provided examples lack comprehensive logic for sanitizing or validating retrieved content before it is interpolated into LLM prompts.
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and content from well-known external sources including Python's official documentation at
docs.python.organd NumPy's documentation atdocs.numpy.org.
Audit Metadata