discopy-categorical-computing
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
INTEGRATION.mdfile contains a 'Model Serialization' section that recommends using thepicklemodule to save and load functors (pickle.load). Thepicklemodule is inherently insecure because it can execute arbitrary code during the deserialization process. Using this pattern to load files from untrusted sources could lead to a full system compromise via arbitrary code execution.\n- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing untrusted natural language text into computational diagrams without explicit sanitization or boundary instructions.\n - Ingestion points: Untrusted text is processed by NLP parsers like
BobcatParserandspaCyas demonstrated inINTEGRATION.mdandEXAMPLES.md.\n - Boundary markers: The provided code examples do not utilize delimiters or specific instructions to ignore embedded commands in the input text.\n
- Capability inventory: The skill uses powerful backends like NumPy, PyTorch, and JAX for matrix and quantum circuit simulations, providing a significant computational capability that could be influenced by malicious data.\n
- Sanitization: There is no evidence of sanitization, filtering, or validation of the input strings before they are parsed into diagrams.
Audit Metadata