foundations-information-theory

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file access or network operations were identified. The included utility, scripts/discrete_information.py, uses only the standard math and json libraries and does not perform any network exfiltration or credential harvesting.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill documentation references external GitHub repositories (e.g., tonellolab/fDIME and LMBTough/NIB) and academic portals (e.g., IEEE, Nature, arXiv) for research and reference purposes. These resources are provided as citations for practitioners and are not downloaded, installed, or executed by the skill itself.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for analyzing external data through information-theoretic primitives.
  • Ingestion points: Numerical probability distributions and joint tables provided as input to scripts/discrete_information.py.
  • Boundary markers: The SKILL.md workflow and references/practical-contract.md provide clear guidelines on defining random variables and sampling frames before computation.
  • Capability inventory: The script is limited to arithmetic and logarithmic operations. It does not have access to high-risk tools like subprocesses, file-system writing, or network requests.
  • Sanitization: The pmf function in scripts/discrete_information.py performs strict input validation, ensuring that all probability inputs are finite, non-negative, and sum to one, which prevents logic-based injection or exploitation during data processing.
  • [SAFE]: All mathematical formulas, theorems, and chapter attributions have been cited against reputable primary sources such as Cover & Thomas and MacKay. No deceptive metadata or prompt injection patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — foundations-information-theory