first-order-odes
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines tool commands and decision tree steps that take string-based inputs for mathematical expressions and initial conditions, which are then processed by shell-executed Python scripts. This creates a surface where maliciously crafted user inputs could attempt to inject commands or bypass logic.
- Ingestion points: The
dsolveandsolvearguments in tool commands withinSKILL.mdaccept arbitrary mathematical strings from the user. - Boundary markers: The examples use double quotes as delimiters for mathematical expressions (e.g.,
"Derivative(y,x) + y"), which provides a basic but bypassable boundary. - Capability inventory: The skill uses the
Bashtool to invokeuv run pythonand internal scripts (scripts/sympy_compute.py,scripts/z3_solve.py). - Sanitization: There is no evidence of sanitization, escaping, or strict schema validation for the user-provided expressions within the instruction file.
Audit Metadata