foundations-mathematical-optimization
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The unit test script
scripts/test_lp_certificate.pyutilizessubprocess.runto execute thecheck_lp_certificate.pyutility. These calls are restricted to executing the skill's own local scripts using the current Python interpreter and hardcoded test data to verify CLI behavior. - [INDIRECT_PROMPT_INJECTION]: The skill provides a Python utility that processes user-supplied JSON data representing mathematical optimization problems, which presents a potential injection surface.
- Ingestion points: The
scripts/check_lp_certificate.pyscript reads data from files or standard input provided to the command-line interface. - Boundary markers: The script strictly enforces a JSON schema requiring specific keys (
A,b,c,x,y) and rejects any unexpected or duplicate keys. - Capability inventory: The skill performs file reads (
Path.read_text) and executes its own scripts viasubprocess.runin a testing context. It does not perform network operations. - Sanitization: All input scalars are validated against a strict regular expression for decimal numbers and limited to 1,000 characters and a specific exponent magnitude. Data is converted to
fractions.Fractionfor exact arithmetic, preventing interpretation as code or instructions.
Audit Metadata