math-router

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user math intent through a local script to generate executable shell commands. * Ingestion points: User requests are passed as raw string arguments to scripts/cc_math/math_router.py in the routing step. * Boundary markers: None are defined; the user input is interpolated directly into the command line. * Capability inventory: The agent is granted shell execution capability via the instruction to run the command returned by the router. * Sanitization: There is no mention of sanitization, input validation, or output filtering for the generated command strings.
  • [DYNAMIC_EXECUTION]: The skill workflow involves generating a command string at runtime and instructing the agent to execute it. The agent runs math_router.py, which returns a JSON object containing a command field, and the instructions explicitly tell the agent to execute that returned command.
  • [COMMAND_EXECUTION]: The skill relies on executing various local Python scripts (e.g., math_router.py, sympy_compute.py) via the uv tool to perform its primary mathematical routing and computation functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — math-router