analytic-functions
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute Python scripts located in thescripts/directory, specificallysympy_compute.pyandz3_solve.py, to perform mathematical computations. - [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-controllable mathematical expressions directly into shell command templates, creating an attack surface where malicious input could lead to command execution.
- Ingestion points: User-provided strings for mathematical functions
u(x,y),v(x,y), andf(z)are passed as arguments to the scripts via theBashtool. - Boundary markers: The skill lacks explicit delimiters or instructions to the agent to treat these inputs as data only, increasing the risk that embedded instructions might be executed.
- Capability inventory: The skill has access to the
Bashtool for running subprocesses and theReadtool for accessing files. - Sanitization: There is no evidence of input validation, escaping, or sanitization to ensure that the mathematical expressions do not contain shell metacharacters or malicious code.
Audit Metadata