python-executor

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill is built to execute arbitrary Python code in a remote environment via the inference.sh service. While the skill description claims a sandboxed environment, the ability to run arbitrary code is a significant capability that must be managed carefully by the agent platform.
  • [COMMAND_EXECUTION]: The skill relies on and invokes the belt command-line tool, which is used to authenticate and run applications on the inference.sh infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation links to a GitHub-hosted repository for the installation of the belt CLI tool (https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md).
  • [INDIRECT_PROMPT_INJECTION]: As a code execution tool, this skill presents a surface for indirect prompt injection. If the AI agent incorporates untrusted content from the user or a third-party source into the code block it executes, that content could potentially run malicious operations.
  • Ingestion points: The code field in the input schema is the primary entry point for untrusted instructions.
  • Boundary markers: There are no delimiters or specific instructions to separate data from code provided in the schema.
  • Capability inventory: The environment allows for network requests (requests, httpx), browser automation (selenium, playwright), and extensive data processing, which could be leveraged for data exfiltration or automated attacks if subverted.
  • Sanitization: The skill does not perform any validation or sanitization on the provided Python code string before passing it to the CLI for execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — python-executor