continuity

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines templates for shell commands that interpolate untrusted input, such as mathematical functions, directly into command arguments without sanitization.\n
  • Ingestion points: Mathematical functions (e.g., "f(x)") and variables (e.g., "a") are ingested from the user's prompt or the current conversation context within SKILL.md.\n
  • Boundary markers: No boundary markers, delimiters, or "ignore embedded instructions" warnings are present to prevent the agent from executing shell-active characters contained within the input.\n
  • Capability inventory: The skill leverages the Bash tool to execute scripts such as scripts/sympy_compute.py and scripts/z3_solve.py.\n
  • Sanitization: There is no evidence of input validation, shell-escaping, or sanitization before the parameters are passed to the Bash tool.\n- [COMMAND_EXECUTION]: The skill relies on the Bash tool to perform its primary functions, specifically using the uv package manager to run local Python modules (runtime.harness) and scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — continuity