convergence
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands via
uv runto invoke local Python scripts (scripts/sympy_compute.pyandscripts/z3_solve.py) for mathematical computation and proving. - [INDIRECT_PROMPT_INJECTION]: The skill takes mathematical expressions (e.g., sequences, series, or logic bounds) from the user and passes them as arguments to external scripts.
- Ingestion points: User-provided math expressions used in the
Sympy_Limit,Sympy_Sum, andZ3_Provetools. - Boundary markers: None present to distinguish mathematical input from instructions.
- Capability inventory: Execution of local Python scripts through the
Bashtool using theuvpackage manager. - Sanitization: No sanitization or validation of the input strings is mentioned in the skill instructions, relying on the target scripts to handle malformed or malicious inputs.
Audit Metadata