dspy-categorical

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements a calculator function within the ReAct module examples that uses the Python eval() built-in function to process strings. This allows for the execution of arbitrary Python expressions.
  • Evidence: return eval(expression) in calculator(expression: str).
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a reasoning pipeline using the dspy.ReAct functor which ingests untrusted user input (the question parameter) and uses an LLM to generate the expression passed to the eval()-based tool. There are no boundary markers, input sanitization, or safety filters present to prevent the model from generating malicious code sequences (e.g., __import__('os').system('...')) if the input prompt is adversarial.
  • Ingestion Point: forward(self, question) and react(question=...) in SKILL.md.
  • Capability Inventory: Python eval() sink in the calculator function.
  • Boundary Markers: None.
  • Sanitization: None.
  • [COMMAND_EXECUTION]: Because eval() can access Python's runtime environment, it can be leveraged to execute system commands through module imports or property access, leading to full system compromise depending on the execution context of the agent.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the dspy-ai package via pip. While this is a standard library for the demonstrated framework, it introduces a third-party dependency into the environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — dspy-categorical