modular-arithmetic

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute internal Python scripts (scripts/sympy_compute.py and scripts/z3_solve.py) via the uv run command to perform mathematical computations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through mathematical inputs. Ingestion points: Equations and logic proofs are accepted as string arguments to shell commands within SKILL.md. Boundary markers: The instructions do not employ delimiters to isolate these inputs from the command context. Capability inventory: The skill is granted Bash and Read permissions, enabling the execution of scripts that perform complex logic. Sanitization: No sanitization, escaping, or validation logic for the input strings is described in the skill content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — modular-arithmetic