prime-numbers

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied mathematical variables and expressions through shell commands, creating a potential attack surface for indirect prompt injection.
  • Ingestion points: User input is interpolated into command arguments for scripts like scripts/sympy_compute.py and scripts/z3_solve.py in SKILL.md.
  • Boundary markers: The skill does not provide explicit delimiters or instructions to the agent to prevent the interpretation of embedded instructions within the mathematical data.
  • Capability inventory: The skill has the capability to execute shell commands via the Bash tool and read files via the Read tool.
  • Sanitization: No sanitization or validation logic for the interpolated variables (e.g., "n", "pi(x)") is visible in the skill instructions.
  • [COMMAND_EXECUTION]: The skill defines multiple tool commands that invoke the Bash tool to run local Python scripts using uv run. While these scripts appear to be vendor-provided tools for mathematical computation, the pattern of interpolating user-controlled strings directly into shell command arguments is a known risk for command injection if the harness or scripts do not implement strict validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — prime-numbers