residues

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates mathematical computations by executing local scripts (scripts/sympy_compute.py and scripts/z3_solve.py) through the Bash tool. These executions are performed using the uv runner within a specified runtime harness.
  • [INDIRECT_PROMPT_INJECTION]: Both SKILL.md and SKILL.v6.md provide templates that interpolate user-provided strings—such as mathematical functions f(z) and pole locations z0—into shell commands. This pattern presents a vulnerability where specially crafted user input containing shell metacharacters could lead to unauthorized command execution.
  • Ingestion points: Mathematical function expressions, variable names, and numerical values for singularities and contours provided by the user at runtime.
  • Boundary markers: The instructions do not specify any quoting, escaping, or boundary markers to isolate user input from the surrounding shell command syntax.
  • Capability inventory: The skill is authorized to use Bash for command execution and Read for file access, providing a path for potential command-based attacks.
  • Sanitization: No explicit sanitization or input validation logic is described in the provided skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — residues