compactness

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions define shell command templates that ingest untrusted user data (mathematical expressions and variables) without explicit sanitization.
  • Ingestion points: User-provided inputs such as function definitions ("f(x)"), sequence terms ("a_n"), and domain ranges ("[a,b]") are interpolated directly into shell command strings in SKILL.md.
  • Boundary markers: There are no boundary markers or instructions to the agent to escape shell metacharacters in the user input.
  • Capability inventory: The skill utilizes the Bash tool to execute Python scripts via uv run.
  • Sanitization: No sanitization or validation logic is present to prevent command injection if a user provides a malicious string instead of a mathematical expression.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute scripts (z3_solve.py, sympy_compute.py) via the uv run python command. While this is the intended functionality for solving math problems, it represents a privilege surface that is combined with the untrusted data ingestion mentioned above.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — compactness