jupyter-notebook
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv runto execute a local Python script (scripts/new_notebook.py) for scaffolding notebooks from templates. It also suggests usinguv pipto install standard Jupyter packages (jupyterlab,ipykernel) for local execution. These are standard development workflows and follow best practices for dependency management. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied instructions to generate notebook content. While this content is subsequently placed in executable cells within a Jupyter notebook, the skill uses a controlled scaffolding process (Python script + JSON templates) rather than direct string interpolation into a shell, which reduces the risk of malicious command injection. The vulnerability surface is limited to the notebook environment itself.
- Ingestion points: User instructions for notebook objectives and content processed in
SKILL.mdandnew_notebook.py. - Boundary markers: Not explicitly defined in the helper script, but content is structured within JSON cell objects.
- Capability inventory: Local file writing and script execution (
new_notebook.py), plus suggested notebook execution viajupyterlab. - Sanitization: Titles are slugified before being used in filenames to prevent path traversal.
Audit Metadata