sigma-algebras

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [METADATA_POISONING]: The skill's 'Key Techniques' section contains multiple references to 'Z-Library'. Z-Library is a known shadow library and piracy site; referencing such sources may violate intellectual property policies.
  • [INDIRECT_PROMPT_INJECTION]: The skill executes Python scripts via the Bash tool using arguments derived from mathematical or logical expressions, creating a surface for injection if the input is not sanitized.
  • Ingestion points: Mathematical expressions and logical predicates are passed as command-line arguments to z3_solve.py and sympy_compute.py in the 'Tool Commands' section of SKILL.md.
  • Boundary markers: There are no visible boundary markers or instructions within the command templates to delimit user-provided expressions from the command structure.
  • Capability inventory: The skill is granted Bash tool access and utilizes uv run to execute local Python scripts.
  • Sanitization: The provided instructions do not include any steps for sanitizing, escaping, or validating the logical strings before they are passed to the shell-based scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — sigma-algebras