limits
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts mathematical expressions from the user and passes them as arguments to CLI scripts, creating a potential surface for injection if the inputs contain malicious shell characters or instructions.
- Ingestion points: User-provided limit expressions (e.g., "sin(x)/x") processed in SKILL.md.
- Boundary markers: None identified; expressions are interpolated directly into shell commands.
- Capability inventory: Execution of Python scripts (sympy_compute.py, z3_solve.py) via
uv runwith access to theBashandReadtools. - Sanitization: The instructions do not specify any validation or sanitization mechanisms for the input strings before they are passed to the shell.
Audit Metadata