effect-ts-ai
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides an example implementation of a
CalculatorToolthat uses theeval()function to execute logic. Because the input to this tool is generated by a language model based on user requests, an attacker could use prompt injection to trick the model into generating malicious JavaScript instead of a mathematical expression, leading to arbitrary code execution within the environment. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for interpolating untrusted external data directly into language model prompts without the use of boundary markers or explicit sanitization instructions. This makes the system susceptible to instructions hidden within the data it processes.
- Ingestion points: The
analyzeSentimentfunction accepts atextparameter that is interpolated directly into a string template for the language model prompt. - Boundary markers: The prompt templates in the examples do not include delimiters or specific instructions for the model to treat the input as data only.
- Capability inventory: The skill defines a toolkit with capabilities for calculating expressions (via
eval) and retrieving weather information. - Sanitization: There is no demonstration of escaping, validation, or filtering for the external text before it is sent to the model or for the expressions sent to the evaluation tool.
Audit Metadata