skills/openhands/extensions/jupyter/Gen Agent Trust Hub

jupyter

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the jupyter nbconvert CLI tool and local shell commands like grep to interact with and transform notebook files.
  • [DYNAMIC_EXECUTION]: The skill facilitates the execution of code stored within .ipynb files using the jupyter nbconvert --execute command, which is the primary intended functionality for data science workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on Jupyter notebooks, which are external data sources that can contain arbitrary code or instructions.
  • Ingestion points: Processes .ipynb files from the local file system using Python's json module and the jupyter CLI tool.
  • Boundary markers: None; the instructions provide direct programmatic access to notebook cells for modification and execution.
  • Capability inventory: Local file writing, shell command execution (jupyter, grep, Select-String), and Python script execution.
  • Sanitization: None; the skill provides raw programmatic access to notebook data structures to facilitate editing and clearing outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — jupyter