numerical-integration
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides shell commands that use
uv run python -cto execute Python code snippets for numerical integration, which is a standard agent capability but involves direct shell interaction. - [INDIRECT_PROMPT_INJECTION]: The skill defines decision-tree steps and command templates that incorporate mathematical expressions provided by the user (e.g.,
integrate "f(x)"). This represents a vulnerability surface if those expressions are sourced from untrusted external data without sanitization. - Ingestion points: Mathematical expressions are passed as arguments to
sympy_compute.pyandpython -cwithinSKILL.md. - Boundary markers: None are present in the command templates to delimit untrusted input.
- Capability inventory: Uses the
Bashtool to execute Python one-liners and the local scriptscripts/sympy_compute.py. - Sanitization: There is no evidence of sanitization, escaping, or validation logic for the input expressions before they are executed in the shell.
Audit Metadata