shapely-compute

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts external geometric data (WKT strings and coordinate lists) as input for various computational tasks, creating an attack surface for indirect prompt injection where instructions could be hidden in geometric data.
  • Ingestion points: The --coords, --g1, --g2, and --geom arguments used in the create, op, pred, measure, distance, transform, validate, coords, and fromwkt commands within SKILL.md.
  • Boundary markers: The instructions do not define boundary markers or provide the agent with instructions to ignore potential commands embedded in the geometry data.
  • Capability inventory: The skill executes a Python script (scripts/shapely_compute.py) via the uv tool to perform operations based on the input.
  • Sanitization: The skill description does not specify any sanitization or validation routines for the input strings before they are processed by the underlying script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — shapely-compute