sigma-algebras
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [METADATA_POISONING]: The skill's 'Key Techniques' section contains multiple references to 'Z-Library'. Z-Library is a known shadow library and piracy site; referencing such sources may violate intellectual property policies.
- [INDIRECT_PROMPT_INJECTION]: The skill executes Python scripts via the
Bashtool using arguments derived from mathematical or logical expressions, creating a surface for injection if the input is not sanitized. - Ingestion points: Mathematical expressions and logical predicates are passed as command-line arguments to
z3_solve.pyandsympy_compute.pyin the 'Tool Commands' section of SKILL.md. - Boundary markers: There are no visible boundary markers or instructions within the command templates to delimit user-provided expressions from the command structure.
- Capability inventory: The skill is granted
Bashtool access and utilizesuv runto execute local Python scripts. - Sanitization: The provided instructions do not include any steps for sanitizing, escaping, or validating the logical strings before they are passed to the shell-based scripts.
Audit Metadata