residues
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates mathematical computations by executing local scripts (scripts/sympy_compute.py and scripts/z3_solve.py) through the Bash tool. These executions are performed using the uv runner within a specified runtime harness.
- [INDIRECT_PROMPT_INJECTION]: Both SKILL.md and SKILL.v6.md provide templates that interpolate user-provided strings—such as mathematical functions f(z) and pole locations z0—into shell commands. This pattern presents a vulnerability where specially crafted user input containing shell metacharacters could lead to unauthorized command execution.
- Ingestion points: Mathematical function expressions, variable names, and numerical values for singularities and contours provided by the user at runtime.
- Boundary markers: The instructions do not specify any quoting, escaping, or boundary markers to isolate user input from the surrounding shell command syntax.
- Capability inventory: The skill is authorized to use Bash for command execution and Read for file access, providing a path for potential command-based attacks.
- Sanitization: No explicit sanitization or input validation logic is described in the provided skill files.
Audit Metadata