root-finding

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to incorporate user-provided mathematical expressions into shell commands executed via the Bash tool. This pattern is susceptible to indirect prompt injection where maliciously crafted expressions could attempt to escape the command context or influence script behavior. * Ingestion points: Expressions passed as arguments to scripts/sympy_compute.py and z3_solve.py. * Boundary markers: None identified; inputs are interpolated directly into shell command templates. * Capability inventory: Access to the Bash tool for executing Python one-liners and local scripts. * Sanitization: No instructions for input validation or sanitization are included.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform numerical analysis and execute local utility scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — root-finding