limits-colimits

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a command uv run python -m runtime.harness scripts/sympy_compute.py solve "f(a) == g(b)" that interpolates user-provided mathematical expressions into a Python script. While this creates a surface for indirect prompt injection, it is restricted to the context of mathematical computation and uses standard tool harnessing.
  • Ingestion points: User-provided mathematical expressions in SKILL.md.
  • Boundary markers: None explicitly defined in the prompt template.
  • Capability inventory: Execution of local scripts via uv run and lake build via the Bash tool.
  • Sanitization: Relies on the external scripts/sympy_compute.py and the agent's internal safety filters.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute lake build for Lean 4 verification and uv run for Python-based computations. These are standard developer operations within the scope of the skill's mathematical purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — limits-colimits