math

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute Python scripts located in the project's internal scripts directory ($CLAUDE_PROJECT_DIR/.claude/scripts/cc_math/). It passes user-provided expressions and variables as command-line arguments to scripts such as sympy_compute.py, z3_solve.py, and pint_compute.py via the uv runtime.- [INDIRECT_PROMPT_INJECTION]: The skill represents a vulnerability surface for indirect prompt injection by taking untrusted natural language requests and interpolating them into shell commands.
  • Ingestion points: User-provided equations, variables, conversion values, and general natural language math queries.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined, although script examples demonstrate the use of double quotes for shell arguments.
  • Capability inventory: Execution of arbitrary Bash commands and Python scripts with access to the local filesystem (Read/Write).
  • Sanitization: No explicit sanitization, validation, or escaping of external user content is documented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:11 PM
Security Audit — agent-trust-hub — math