deno-sandbox

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and execute untrusted user or AI-generated code, creating a surface for indirect prompt injection.
  • Ingestion points: The functions runUserCode(code), executePlayground(code), and executeAgentTool(toolCode, input) in SKILL.md accept external strings as code for execution.
  • Boundary markers: The skill advocates for the use of Deno's internal permission system (e.g., --allow-none, --allow-net) to restrict the sandboxed process's capabilities, though these markers do not prevent the injection itself.
  • Capability inventory: The skill utilizes sandbox.spawn to run commands and sandbox.fs.writeFile to persist untrusted content to the sandbox filesystem.
  • Sanitization: The documentation demonstrates wrapping input in JSON.stringify() for the executeAgentTool wrapper and provides specific advice on validating and parsing sandbox output as JSON data rather than executing it.
  • [DYNAMIC_EXECUTION]: The skill demonstrates and promotes the generation and execution of scripts at runtime.
  • Evidence: Multiple examples (e.g., the 'Code Playground' and 'AI Agent Tool Execution' sections) show strings being written to files like /playground/main.ts or /tool.ts and subsequently executed using the deno run command via sandbox.spawn.
  • Context: This dynamic execution is the core intended functionality of the skill. It is implemented via the Deno Sandbox SDK, which utilizes Firecracker microVMs to provide a secure, isolated environment specifically designed for this purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — deno-sandbox