continuity
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines templates for shell commands that interpolate untrusted input, such as mathematical functions, directly into command arguments without sanitization.\n
- Ingestion points: Mathematical functions (e.g., "f(x)") and variables (e.g., "a") are ingested from the user's prompt or the current conversation context within
SKILL.md.\n - Boundary markers: No boundary markers, delimiters, or "ignore embedded instructions" warnings are present to prevent the agent from executing shell-active characters contained within the input.\n
- Capability inventory: The skill leverages the
Bashtool to execute scripts such asscripts/sympy_compute.pyandscripts/z3_solve.py.\n - Sanitization: There is no evidence of input validation, shell-escaping, or sanitization before the parameters are passed to the
Bashtool.\n- [COMMAND_EXECUTION]: The skill relies on theBashtool to perform its primary functions, specifically using theuvpackage manager to run local Python modules (runtime.harness) and scripts.
Audit Metadata