contour-integrals

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill takes user-supplied mathematical expressions and passes them as string arguments to a local computation script via the Bash tool.
  • Ingestion points: Mathematical functions such as f(z) and f(x) are accepted as input for residue calculation, pole finding, and integration tools mentioned in SKILL.md.
  • Boundary markers: The instructions recommend wrapping expressions in double quotes (e.g., "1/(z**2 + 1)"), which provides a basic but bypassable delimiter.
  • Capability inventory: The skill uses the Bash tool to execute uv run python commands and the Read tool to access files.
  • Sanitization: There is no evidence of input validation or escaping for the mathematical strings before they are passed to the sympy_compute.py script, which may lead to command or code injection if the script handles inputs unsafely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — contour-integrals