discopy-categorical-computing

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The INTEGRATION.md file contains a 'Model Serialization' section that recommends using the pickle module to save and load functors (pickle.load). The pickle module is inherently insecure because it can execute arbitrary code during the deserialization process. Using this pattern to load files from untrusted sources could lead to a full system compromise via arbitrary code execution.\n- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing untrusted natural language text into computational diagrams without explicit sanitization or boundary instructions.\n
  • Ingestion points: Untrusted text is processed by NLP parsers like BobcatParser and spaCy as demonstrated in INTEGRATION.md and EXAMPLES.md.\n
  • Boundary markers: The provided code examples do not utilize delimiters or specific instructions to ignore embedded commands in the input text.\n
  • Capability inventory: The skill uses powerful backends like NumPy, PyTorch, and JAX for matrix and quantum circuit simulations, providing a significant computational capability that could be influenced by malicious data.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the input strings before they are parsed into diagrams.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — discopy-categorical-computing