limits-colimits
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes a command
uv run python -m runtime.harness scripts/sympy_compute.py solve "f(a) == g(b)"that interpolates user-provided mathematical expressions into a Python script. While this creates a surface for indirect prompt injection, it is restricted to the context of mathematical computation and uses standard tool harnessing. - Ingestion points: User-provided mathematical expressions in
SKILL.md. - Boundary markers: None explicitly defined in the prompt template.
- Capability inventory: Execution of local scripts via
uv runandlake buildvia the Bash tool. - Sanitization: Relies on the external
scripts/sympy_compute.pyand the agent's internal safety filters. - [COMMAND_EXECUTION]: The skill uses the Bash tool to execute
lake buildfor Lean 4 verification anduv runfor Python-based computations. These are standard developer operations within the scope of the skill's mathematical purpose.
Audit Metadata