maths-olympiad

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages local execution environments, specifically Bash and Python, within its 'Deep Mode' and PDF compilation scripts mentioned in the documentation. These tools are intended for mathematical verification and document generation, and the skill contains explicit instructions to prevent network activity during these processes.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface where user-supplied problem statements are processed by multiple agents, some with code execution privileges.
  • Ingestion points: Problem statements are interpolated into agent prompts in SKILL.md (Steps 2 and 6c).
  • Boundary markers: The input is delineated using simple textual markers like 'PROBLEM:', which provides minimal protection against adversarial input.
  • Capability inventory: The 'Deep Mode' agent is explicitly permitted to use Bash and Python for computation as described in the workflow instructions.
  • Sanitization: No explicit sanitization or input validation logic is described for the problem statements before they are passed to sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 02:25 PM
Security Audit — agent-trust-hub — maths-olympiad