openai-agents

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The documentation includes a code example for a 'calculate' tool that uses Python's built-in eval() function to process string expressions.\n
  • Evidence: The calculate function snippet in SKILL.md uses result = eval(expression) to evaluate the tool input.\n
  • Risk: Since tool inputs are generated by the LLM based on user prompts, using eval() creates a direct path for arbitrary code execution on the host environment if a malicious user provides an injection that influences the tool call.\n
  • Mitigation: The skill includes a code comment advising the use of ast.literal_eval or a math parser for production, which reduces the severity from high to low for this documentation-focused skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 04:12 PM
Security Audit — agent-trust-hub — openai-agents