prime-numbers
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied mathematical variables and expressions through shell commands, creating a potential attack surface for indirect prompt injection.
- Ingestion points: User input is interpolated into command arguments for scripts like
scripts/sympy_compute.pyandscripts/z3_solve.pyinSKILL.md. - Boundary markers: The skill does not provide explicit delimiters or instructions to the agent to prevent the interpretation of embedded instructions within the mathematical data.
- Capability inventory: The skill has the capability to execute shell commands via the
Bashtool and read files via theReadtool. - Sanitization: No sanitization or validation logic for the interpolated variables (e.g., "n", "pi(x)") is visible in the skill instructions.
- [COMMAND_EXECUTION]: The skill defines multiple tool commands that invoke the
Bashtool to run local Python scripts usinguv run. While these scripts appear to be vendor-provided tools for mathematical computation, the pattern of interpolating user-controlled strings directly into shell command arguments is a known risk for command injection if the harness or scripts do not implement strict validation.
Audit Metadata