open-sets

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of user-supplied mathematical proofs by executing a Python-based Z3 solver (scripts/z3_solve.py) through shell commands. While the provided commands use static logic strings, the skill's primary purpose involves adapting these commands to specific user problems, which introduces a risk of injection if the solver or shell environment does not properly handle interpolated data. The instructions lack explicit boundary markers or sanitization guidelines for the agent to follow when constructing these commands.\n
  • Ingestion points: Topological problem definitions and proof attempts provided by the user in the conversation context.\n
  • Boundary markers: Not present; the skill does not instruct the agent to use delimiters or ignore instructions embedded within the mathematical data.\n
  • Capability inventory: The skill utilizes the Bash tool to execute shell commands (uv run) to invoke a Python script with string arguments.\n
  • Sanitization: No sanitization or validation logic is specified for the strings passed as arguments to the Z3 solver script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — open-sets