matlab
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it reads and processes user-provided MATLAB source files (.m), archives (.mlx), and binary data files (.mat).
- Ingestion points: The scripts
scan_m_code.pyandinventory_mat_file.pyingest the contents of external files to perform risk triage and metadata extraction. - Boundary markers: The skill includes extensive instructions in
SKILL.mddefining a 'Nonnegotiable safety boundary' that directs the agent to treat all processed files as untrusted execution surfaces and to avoid implicit execution. - Capability inventory: The skill utilizes
BashandPythontools. It can write new files viagenerate_function_scaffold.pyand output shell command plans viaplan_batch_command.py. - Sanitization: The skill implements robust sanitization in
_common.py, usingPath.resolve(strict=True)to prevent directory traversal, rejecting all symlink components in file paths, and enforcing hard limits on input file sizes (64MB) and JSON nesting depth. - [SAFE]: The included Python helper scripts are designed with a high security priority. They operate in a network-free mode, refuse to follow symlinks, and avoid the deserialization of complex objects or the use of dynamic execution functions like
eval()orexec(). The tools focus on providing metadata and static reports rather than active execution. - [EXTERNAL_DOWNLOADS]: The skill references the
matlabenginePython package, which is the official MathWorks library. These references are provided neutrally for environment configuration and target well-known, trusted package registries.
Audit Metadata