polymath
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill ingests external data from the web to provide research insights.
- Ingestion points: search_web, read_url_content, and secure_crawl are used in SKILL.md and modes/research.md to fetch data.
- Boundary markers: The skill synthesizes information into structured templates, though it does not explicitly use delimiters for external data.
- Capability inventory: The skill can read workspace files and interacts with users via notify_user across all modes.
- Sanitization: The skill includes specific instructions to sanitize content from deep crawls to prevent processing malicious payloads.
- [COMMAND_EXECUTION]: The skill uses dynamic context injection to initialize its state.
- Evidence: SKILL.md uses the !cat command to read project-specific configuration and context files from the repository at startup.
- Context: These operations are restricted to non-sensitive project artifacts and are used to provide the agent with necessary project orientation.
Audit Metadata