matlab

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it reads and processes user-provided MATLAB source files (.m), archives (.mlx), and binary data files (.mat).
  • Ingestion points: The scripts scan_m_code.py and inventory_mat_file.py ingest the contents of external files to perform risk triage and metadata extraction.
  • Boundary markers: The skill includes extensive instructions in SKILL.md defining a 'Nonnegotiable safety boundary' that directs the agent to treat all processed files as untrusted execution surfaces and to avoid implicit execution.
  • Capability inventory: The skill utilizes Bash and Python tools. It can write new files via generate_function_scaffold.py and output shell command plans via plan_batch_command.py.
  • Sanitization: The skill implements robust sanitization in _common.py, using Path.resolve(strict=True) to prevent directory traversal, rejecting all symlink components in file paths, and enforcing hard limits on input file sizes (64MB) and JSON nesting depth.
  • [SAFE]: The included Python helper scripts are designed with a high security priority. They operate in a network-free mode, refuse to follow symlinks, and avoid the deserialization of complex objects or the use of dynamic execution functions like eval() or exec(). The tools focus on providing metadata and static reports rather than active execution.
  • [EXTERNAL_DOWNLOADS]: The skill references the matlabengine Python package, which is the official MathWorks library. These references are provided neutrally for environment configuration and target well-known, trusted package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — matlab