limits

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts mathematical expressions from the user and passes them as arguments to CLI scripts, creating a potential surface for injection if the inputs contain malicious shell characters or instructions.
  • Ingestion points: User-provided limit expressions (e.g., "sin(x)/x") processed in SKILL.md.
  • Boundary markers: None identified; expressions are interpolated directly into shell commands.
  • Capability inventory: Execution of Python scripts (sympy_compute.py, z3_solve.py) via uv run with access to the Bash and Read tools.
  • Sanitization: The instructions do not specify any validation or sanitization mechanisms for the input strings before they are passed to the shell.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — limits