groups
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute local Python scripts
z3_solve.pyandsympy_compute.pyvia theuvrunner to perform formal verification and simplification of algebraic expressions. - [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for untrusted user input to be passed directly to shell command arguments.
- Ingestion points: User-supplied group definitions, mathematical axioms, and algebraic operations provided in the prompt context.
- Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions embedded within the mathematical strings provided to the solvers.
- Capability inventory: The Bash tool is used to execute Python modules with string arguments derived from user input.
- Sanitization: Absent; the skill does not specify any logic for escaping shell-sensitive characters or validating the structure of the mathematical input before it is passed to the shell.
Audit Metadata