sympy
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill demonstrates the use of
autowrapandufuncifyinreferences/code-generation-printing.md. These functions compile C or Fortran source code at runtime and link the resulting binaries into the process. - [DYNAMIC_EXECUTION]: The skill provides examples of
lambdifyinSKILL.mdandreferences/code-generation-printing.md, which generates and executes Python code from symbolic expressions. - [DYNAMIC_EXECUTION]: In
references/code-generation-printing.md, the skill shows how to usepickle.load()for deserialization. This is a known unsafe deserialization vector if used on untrusted data. - [DYNAMIC_EXECUTION]: The skill documents string-based parsing using
parse_expr(),parse_latex(), andparse_mathematica()inreferences/code-generation-printing.md, which creates an injection surface for malicious mathematical expressions.
Audit Metadata