analytic-functions

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute Python scripts located in the scripts/ directory, specifically sympy_compute.py and z3_solve.py, to perform mathematical computations.
  • [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-controllable mathematical expressions directly into shell command templates, creating an attack surface where malicious input could lead to command execution.
  • Ingestion points: User-provided strings for mathematical functions u(x,y), v(x,y), and f(z) are passed as arguments to the scripts via the Bash tool.
  • Boundary markers: The skill lacks explicit delimiters or instructions to the agent to treat these inputs as data only, increasing the risk that embedded instructions might be executed.
  • Capability inventory: The skill has access to the Bash tool for running subprocesses and the Read tool for accessing files.
  • Sanitization: There is no evidence of input validation, escaping, or sanitization to ensure that the mathematical expressions do not contain shell metacharacters or malicious code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — analytic-functions