math
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute Python scripts located in the project's internal scripts directory ($CLAUDE_PROJECT_DIR/.claude/scripts/cc_math/). It passes user-provided expressions and variables as command-line arguments to scripts such as sympy_compute.py, z3_solve.py, and pint_compute.py via the uv runtime.- [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerability surface for indirect prompt injection by taking untrusted natural language requests and interpolating them into shell commands.
- Ingestion points: User-provided equations, variables, conversion values, and general natural language math queries.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined, although script examples demonstrate the use of double quotes for shell arguments.
- Capability inventory: Execution of arbitrary Bash commands and Python scripts with access to the local filesystem (Read/Write).
- Sanitization: No explicit sanitization, validation, or escaping of external user content is documented in the skill instructions.
Audit Metadata