Detecting eval / exec Usage

SkillDev tools

Scan a source tree for dynamic-code-execution APIs that an attacker can hijack: Python eval / exec / compile, JavaScript eval / Function() / setTimeout(string), Ruby eval / instance_eval / class_eval, Java ScriptEngine, PHP eval / assert($str), .NET Activator.CreateInstance / Reflection.Emit with dynamic input. Use when: pre-commit gate on any application that parses user-uploaded code (rule engines, formula evaluators, plugin systems), or post-bug-report when "we run user-supplied expressions." Threshold: any call to eval / exec / Function / similar where the argument is not a string literal. Trigger with: "scan eval", "find dynamic exec", "audit eval calls", "code injection patterns".

Use Detecting eval / exec Usage in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Detecting eval / exec Usage and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Detecting eval / exec Usage skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Detecting eval / exec UsageStart free

What this skill tells your AI

The instructions your AI receives, as published by jeremylongshore/tons-of-skills-marketplace in skills/.curated/detecting-eval-exec-usage/SKILL.md and read by Ahel’s review.

Overview

Dynamic-code-execution APIs (CWE-95 Eval Injection) let an application interpret a string as code at runtime. If the string contains anything user-controllable, the application has handed the attacker arbitrary code execution.

The defensive posture: don't use these APIs. The exceptions are narrow: rule engines, formula evaluators (spreadsheet = formulas), plugin systems with explicit sandboxing. For everything else, there's almost always a safer alternative.

When the skill produces findings

FindingSeverityThresholdAffected control
Python eval(...) with non-literalCRITICALargument contains var refCWE-95
Python exec(...) with non-literalCRITICALargument contains var refCWE-95
Python compile(...) with non-literalHIGHsource string contains varCWE-95
Python __import__(var)HIGHdynamic module loadingCWE-95
JS eval(...)CRITICALanyCWE-95
JS new Function(str)CRITICALany non-literalCWE-95
JS setTimeout/setInterval(string)HIGHstring instead of functionCWE-95
Ruby eval(...)/instance_eval(...)/class_eval(...)CRITICALnon-literalCWE-95
PHP eval(...)CRITICALalwaysCWE-95
PHP assert($str)CRITICAL(legacy code-eval form)CWE-95
PHP create_functionCRITICALdeprecated, eval-equivalentCWE-95
Java ScriptEngineManager + evalHIGHdynamic script executionCWE-95
C# Activator.CreateInstance(Type.GetType(str))HIGHtype loading from stringCWE-95

Prerequisites

  • Python 3.9+
  • Source tree on local filesystem

Instructions

Run

python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-eval-exec-usage/scripts/scan_eval.py /path/to/repo

Options: --output FILE, --format json|jsonl|markdown, --min-severity, --include-tests, --languages LIST.

Interpret

CRITICAL = direct RCE vector. Replace the dynamic execution with explicit logic (lookup table, switch statement) or a sandboxed expression library (Python simpleeval, JavaScript expr-eval, Ruby Dentaku).

Remediation

See references/PLAYBOOK.md.

Examples

Pre-commit

python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-eval-exec-usage/scripts/scan_eval.py \
    --min-severity high $(git diff --name-only main...HEAD | tr '\n' ' ')

CI

- run: |
    python3 plugins/security/penetration-tester/skills/detecting-eval-exec-usage/scripts/scan_eval.py \
        . --min-severity high

Output

JSON / JSONL / Markdown. Exit codes: 0 / 1 / 2.

Error Handling

False positive on eval("'literal'") — the value is a constant string. Verify the regex match by reading the source line.

Resources

  • references/THEORY.md — Why dynamic-code execution is the highest-impact injection class, sandbox limits, the formula-evaluator design pattern
  • references/PLAYBOOK.md — Per-language safe alternatives (Python simpleeval / ast.literal_eval, JS expression-eval libraries, Ruby Dentaku, Java scripting sandboxes)

Signals

GitHub stars
3k
Forks
415
Last commit
Oct 2026
Advanced
Item type
skill
Key
detecting-eval-exec-usage
Source
github.com/jeremylongshore/tons-of-skills-marketplace