OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail4 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
The skill demonstrates a design pattern where the AI agent uses the Python `eval()` function to execute code it generates dynamically. This pattern is highly insecure because it allows a malicious user to gain arbitrary code execution on the system through prompt injection or indirect prompt injection by crafting inputs that cause the model to generate dangerous Python expressions.
Detected behaviors
No alerts
No issues
3 findings · Score: 69/100