convergence

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands via uv run to invoke local Python scripts (scripts/sympy_compute.py and scripts/z3_solve.py) for mathematical computation and proving.
  • [INDIRECT_PROMPT_INJECTION]: The skill takes mathematical expressions (e.g., sequences, series, or logic bounds) from the user and passes them as arguments to external scripts.
  • Ingestion points: User-provided math expressions used in the Sympy_Limit, Sympy_Sum, and Z3_Prove tools.
  • Boundary markers: None present to distinguish mathematical input from instructions.
  • Capability inventory: Execution of local Python scripts through the Bash tool using the uv package manager.
  • Sanitization: No sanitization or validation of the input strings is mentioned in the skill instructions, relying on the target scripts to handle malformed or malicious inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — convergence