dspy-categorical
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements a
calculatorfunction within theReActmodule examples that uses the Pythoneval()built-in function to process strings. This allows for the execution of arbitrary Python expressions. - Evidence:
return eval(expression)incalculator(expression: str). - [INDIRECT_PROMPT_INJECTION]: The skill defines a reasoning pipeline using the
dspy.ReActfunctor which ingests untrusted user input (thequestionparameter) and uses an LLM to generate theexpressionpassed to theeval()-based tool. There are no boundary markers, input sanitization, or safety filters present to prevent the model from generating malicious code sequences (e.g.,__import__('os').system('...')) if the input prompt is adversarial. - Ingestion Point:
forward(self, question)andreact(question=...)inSKILL.md. - Capability Inventory: Python
eval()sink in thecalculatorfunction. - Boundary Markers: None.
- Sanitization: None.
- [COMMAND_EXECUTION]: Because
eval()can access Python's runtime environment, it can be leveraged to execute system commands through module imports or property access, leading to full system compromise depending on the execution context of the agent. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
dspy-aipackage viapip. While this is a standard library for the demonstrated framework, it introduces a third-party dependency into the environment.
Audit Metadata