calculator

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements a safe arithmetic evaluator using Python's ast module. It parses expressions into an Abstract Syntax Tree and recursively evaluates only a strictly whitelisted set of operations (Add, Sub, Mult, Div, Pow, Mod, USub, UAdd) and constants. This approach effectively prevents arbitrary code execution that would be possible if eval() were used.\n- [DATA_EXPOSURE]: The skill is entirely self-contained. Analysis of scripts/calc.py confirms that it does not access the file system (outside of its own arguments), read environment variables, or initiate any network connections.\n- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied strings, the input is strictly validated via regular expressions for conversions and percentage calculations, and via ast.parse(mode='eval') for arithmetic. The use of ast.parse with mode='eval' ensures that only single expressions are accepted, preventing multi-statement injection attacks. Every finding associated with this category follows the mandatory evidence chain: Ingestion points (sys.argv), Boundary markers (none, but syntax-validated), Capability inventory (stdout print only), and Sanitization (strict AST node whitelisting).\n- [UNVERIFIABLE_DEPENDENCIES]: The skill has no external dependencies and uses only Python standard libraries, ensuring a predictable and safe execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:40 PM
Security Audit — agent-trust-hub — calculator