math-visualizer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to generate Python code for mathematical visualizations based on user-provided expressions, formulas, and proofs. This direct interpolation of untrusted data into executable code templates constitutes an indirect prompt injection surface.
- Ingestion points: Mathematical equations, formulas, and derivations provided by the user (as specified in the
triggerssection ofSKILL.md). - Boundary markers: None identified. The templates in
SKILL.mdandtemplates/directly insert user expressions intoMathTexorTexobjects without delimiters or instructions to ignore embedded commands. - Capability inventory: The skill provides structures for generating Python scripts designed for the Manim animation engine. Depending on the environment where the agent executes this Python code, there is a risk of unauthorized command execution if the user provides a malicious LaTeX or Python string.
- Sanitization: There are no instructions or scripts provided to validate or sanitize user input before it is used to generate animation code.
Audit Metadata