sympy
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documents SymPy's capability to generate and execute code at runtime through
lambdify,autowrap, andufuncify. These tools allow symbolic expressions to be converted into optimized Python, C, or Fortran functions. - [INDIRECT_PROMPT_INJECTION]: The skill describes functions for parsing strings into symbolic expressions (e.g.,
parse_expr,parse_latex). These represent a surface for indirect prompt injection if external data is processed. 1. Ingestion points: Parsing utilities inreferences/code-generation-printing.md. 2. Boundary markers: The documentation suggests limiting transformations and using controlled dictionaries. 3. Capability inventory: Code generation and file-writing capabilities. 4. Sanitization: A validation pattern is provided that uses regular expressions to block dangerous syntax likeimportand__. - [DYNAMIC_EXECUTION]: The skill illustrates the use of
picklefor serializing mathematical objects. The documentation contextualizes this for local result saving, a standard persistence pattern.
Audit Metadata