first-order-odes

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines tool commands and decision tree steps that take string-based inputs for mathematical expressions and initial conditions, which are then processed by shell-executed Python scripts. This creates a surface where maliciously crafted user inputs could attempt to inject commands or bypass logic.
  • Ingestion points: The dsolve and solve arguments in tool commands within SKILL.md accept arbitrary mathematical strings from the user.
  • Boundary markers: The examples use double quotes as delimiters for mathematical expressions (e.g., "Derivative(y,x) + y"), which provides a basic but bypassable boundary.
  • Capability inventory: The skill uses the Bash tool to invoke uv run python and internal scripts (scripts/sympy_compute.py, scripts/z3_solve.py).
  • Sanitization: There is no evidence of sanitization, escaping, or strict schema validation for the user-provided expressions within the instruction file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — first-order-odes