compactness
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions define shell command templates that ingest untrusted user data (mathematical expressions and variables) without explicit sanitization.
- Ingestion points: User-provided inputs such as function definitions ("f(x)"), sequence terms ("a_n"), and domain ranges ("[a,b]") are interpolated directly into shell command strings in
SKILL.md. - Boundary markers: There are no boundary markers or instructions to the agent to escape shell metacharacters in the user input.
- Capability inventory: The skill utilizes the
Bashtool to execute Python scripts viauv run. - Sanitization: No sanitization or validation logic is present to prevent command injection if a user provides a malicious string instead of a mathematical expression.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute scripts (z3_solve.py,sympy_compute.py) via theuv run pythoncommand. While this is the intended functionality for solving math problems, it represents a privilege surface that is combined with the untrusted data ingestion mentioned above.
Audit Metadata