deno-sandbox
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and execute untrusted user or AI-generated code, creating a surface for indirect prompt injection.
- Ingestion points: The functions
runUserCode(code),executePlayground(code), andexecuteAgentTool(toolCode, input)inSKILL.mdaccept external strings as code for execution. - Boundary markers: The skill advocates for the use of Deno's internal permission system (e.g.,
--allow-none,--allow-net) to restrict the sandboxed process's capabilities, though these markers do not prevent the injection itself. - Capability inventory: The skill utilizes
sandbox.spawnto run commands andsandbox.fs.writeFileto persist untrusted content to the sandbox filesystem. - Sanitization: The documentation demonstrates wrapping input in
JSON.stringify()for theexecuteAgentToolwrapper and provides specific advice on validating and parsing sandbox output as JSON data rather than executing it. - [DYNAMIC_EXECUTION]: The skill demonstrates and promotes the generation and execution of scripts at runtime.
- Evidence: Multiple examples (e.g., the 'Code Playground' and 'AI Agent Tool Execution' sections) show strings being written to files like
/playground/main.tsor/tool.tsand subsequently executed using thedeno runcommand viasandbox.spawn. - Context: This dynamic execution is the core intended functionality of the skill. It is implemented via the Deno Sandbox SDK, which utilizes Firecracker microVMs to provide a secure, isolated environment specifically designed for this purpose.
Audit Metadata