jupyter-notebook

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute a local Python script (scripts/new_notebook.py) for scaffolding notebooks from templates. It also suggests using uv pip to install standard Jupyter packages (jupyterlab, ipykernel) for local execution. These are standard development workflows and follow best practices for dependency management.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied instructions to generate notebook content. While this content is subsequently placed in executable cells within a Jupyter notebook, the skill uses a controlled scaffolding process (Python script + JSON templates) rather than direct string interpolation into a shell, which reduces the risk of malicious command injection. The vulnerability surface is limited to the notebook environment itself.
  • Ingestion points: User instructions for notebook objectives and content processed in SKILL.md and new_notebook.py.
  • Boundary markers: Not explicitly defined in the helper script, but content is structured within JSON cell objects.
  • Capability inventory: Local file writing and script execution (new_notebook.py), plus suggested notebook execution via jupyterlab.
  • Sanitization: Titles are slugified before being used in filenames to prevent path traversal.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — jupyter-notebook