numerical-integration

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands that use uv run python -c to execute Python code snippets for numerical integration, which is a standard agent capability but involves direct shell interaction.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines decision-tree steps and command templates that incorporate mathematical expressions provided by the user (e.g., integrate "f(x)"). This represents a vulnerability surface if those expressions are sourced from untrusted external data without sanitization.
  • Ingestion points: Mathematical expressions are passed as arguments to sympy_compute.py and python -c within SKILL.md.
  • Boundary markers: None are present in the command templates to delimit untrusted input.
  • Capability inventory: Uses the Bash tool to execute Python one-liners and the local script scripts/sympy_compute.py.
  • Sanitization: There is no evidence of sanitization, escaping, or validation logic for the input expressions before they are executed in the shell.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — numerical-integration