qutip
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes model definitions and simulation results from local JSON files, creating a surface for indirect prompt injection. Ingestion points: The scripts
scripts/qobj_model_validator.pyandscripts/result_audit.pyingest data through theload_json_objectutility. Boundary markers: The skill utilizes a strict JSON loader inscripts/_common.pythat rejects duplicate keys and non-standard constants to maintain data integrity. Capability inventory: The skill executes numerical simulations using the QuTiP library and performs bounded local file I/O, but it lacks general network access or arbitrary command execution capabilities. Sanitization: Input data is strictly validated for type, finiteness, and specific numerical bounds, including limits on Hilbert space dimensions. - [COMMAND_EXECUTION]: The skill provides CLI tools for local quantum simulations that are designed with defensive I/O practices. The
checked_input_fileandchecked_output_filefunctions inscripts/_common.pyexplicitly block the use of network URLs and symbolic links, mitigating risks of unauthorized data access or network communication. - [EXTERNAL_DOWNLOADS]: The documentation guides the installation of specific, pinned versions of the QuTiP library and its extensions from PyPI. These references target established, trusted software ecosystems and do not involve untrusted or unverified sources.
Audit Metadata