uncertainty-and-units

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for scientific calculation tools. It implements a secure mathematical expression evaluator using ast.parse and a strict whitelist of nodes and functions in scripts/_common.py, preventing arbitrary code execution. File operations in the bundled CLIs are protected by checks that reject network URLs and symbolic links, ensuring that all processing remains local to the filesystem. Furthermore, output is written using atomic, private-permissioned temporary files (0600) to protect data integrity. External dependencies are limited to well-known, version-pinned scientific libraries (pint, uncertainties, NumPy, SciPy) sourced from official registries. Analysis of the ingestion points (JSON specification files and mathematical expressions) confirms that robust sanitization and input bounding are in place to mitigate potential indirect injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — uncertainty-and-units