calculator
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements a safe arithmetic evaluator using Python's
astmodule. It parses expressions into an Abstract Syntax Tree and recursively evaluates only a strictly whitelisted set of operations (Add, Sub, Mult, Div, Pow, Mod, USub, UAdd) and constants. This approach effectively prevents arbitrary code execution that would be possible ifeval()were used.\n- [DATA_EXPOSURE]: The skill is entirely self-contained. Analysis ofscripts/calc.pyconfirms that it does not access the file system (outside of its own arguments), read environment variables, or initiate any network connections.\n- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied strings, the input is strictly validated via regular expressions for conversions and percentage calculations, and viaast.parse(mode='eval')for arithmetic. The use ofast.parsewithmode='eval'ensures that only single expressions are accepted, preventing multi-statement injection attacks. Every finding associated with this category follows the mandatory evidence chain: Ingestion points (sys.argv), Boundary markers (none, but syntax-validated), Capability inventory (stdout print only), and Sanitization (strict AST node whitelisting).\n- [UNVERIFIABLE_DEPENDENCIES]: The skill has no external dependencies and uses only Python standard libraries, ensuring a predictable and safe execution environment.
Audit Metadata