guidance

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides examples of a ReAct agent implementation that uses the Python eval() function to execute expressions generated by the LLM. While presented as a calculator tool, this pattern is risky as it allows for arbitrary code execution if the model is successfully prompted to produce malicious code. Evidence: Found in Pattern 4 of SKILL.md and the ReAct Agent section of references/examples.md\n- [DYNAMIC_EXECUTION]: Multiple code examples demonstrate the execution of dynamically generated strings at runtime using eval(). Evidence: tools = {"calculator": lambda expr: eval(expr)}\n- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for processing external, untrusted data (e.g., in extraction and classification tasks) and demonstrates agents with execution capabilities, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: text parameter in extract_entities and classify_article functions; question parameter in react_agent.\n
  • Boundary markers: The skill uses Guidance's grammar-based constraints for structural delimitation, but these do not sanitize content passed to internal execution tools.\n
  • Capability inventory: The eval() function is utilized in the calculator tool example.\n
  • Sanitization: No input sanitization or validation logic is shown for strings passed to the eval() function.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:02 PM