root-finding
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to incorporate user-provided mathematical expressions into shell commands executed via the Bash tool. This pattern is susceptible to indirect prompt injection where maliciously crafted expressions could attempt to escape the command context or influence script behavior. * Ingestion points: Expressions passed as arguments to
scripts/sympy_compute.pyandz3_solve.py. * Boundary markers: None identified; inputs are interpolated directly into shell command templates. * Capability inventory: Access to the Bash tool for executing Python one-liners and local scripts. * Sanitization: No instructions for input validation or sanitization are included. - [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform numerical analysis and execute local utility scripts.
Audit Metadata