fields
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to run Python scripts (z3_solve.py,sympy_compute.py) within auvruntime environment. These scripts are located in the localscripts/directory. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided mathematical data for interpolation into computational commands, which is a potential vulnerability surface.
- Ingestion points: Algebraic expressions and field relations defined by the user in
SKILL.md. - Boundary markers: Absent. User input is placed directly into command arguments without delimiters or 'ignore' instructions.
- Capability inventory: The skill can execute shell commands via the
Bashtool to perform complex calculations. - Sanitization: The instructions do not define any sanitization or validation logic for external mathematical strings before they are processed by the shell harness.
Audit Metadata