guidance
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides examples of a ReAct agent implementation that uses the Python
eval()function to execute expressions generated by the LLM. While presented as a calculator tool, this pattern is risky as it allows for arbitrary code execution if the model is successfully prompted to produce malicious code. Evidence: Found in Pattern 4 ofSKILL.mdand the ReAct Agent section ofreferences/examples.md\n- [DYNAMIC_EXECUTION]: Multiple code examples demonstrate the execution of dynamically generated strings at runtime usingeval(). Evidence:tools = {"calculator": lambda expr: eval(expr)}\n- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for processing external, untrusted data (e.g., in extraction and classification tasks) and demonstrates agents with execution capabilities, creating a surface for indirect prompt injection attacks.\n - Ingestion points:
textparameter inextract_entitiesandclassify_articlefunctions;questionparameter inreact_agent.\n - Boundary markers: The skill uses Guidance's grammar-based constraints for structural delimitation, but these do not sanitize content passed to internal execution tools.\n
- Capability inventory: The
eval()function is utilized in the calculator tool example.\n - Sanitization: No input sanitization or validation logic is shown for strings passed to the
eval()function.
Audit Metadata