python-executor
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill is built to execute arbitrary Python code in a remote environment via the inference.sh service. While the skill description claims a sandboxed environment, the ability to run arbitrary code is a significant capability that must be managed carefully by the agent platform.
- [COMMAND_EXECUTION]: The skill relies on and invokes the
beltcommand-line tool, which is used to authenticate and run applications on the inference.sh infrastructure. - [EXTERNAL_DOWNLOADS]: The skill's documentation links to a GitHub-hosted repository for the installation of the
beltCLI tool (https://raw.githubusercontent.com/inference-sh/skills/refs/heads/main/cli-install.md). - [INDIRECT_PROMPT_INJECTION]: As a code execution tool, this skill presents a surface for indirect prompt injection. If the AI agent incorporates untrusted content from the user or a third-party source into the code block it executes, that content could potentially run malicious operations.
- Ingestion points: The
codefield in the input schema is the primary entry point for untrusted instructions. - Boundary markers: There are no delimiters or specific instructions to separate data from code provided in the schema.
- Capability inventory: The environment allows for network requests (
requests,httpx), browser automation (selenium,playwright), and extensive data processing, which could be leveraged for data exfiltration or automated attacks if subverted. - Sanitization: The skill does not perform any validation or sanitization on the provided Python code string before passing it to the CLI for execution.
Audit Metadata