polymath

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests external data from the web to provide research insights.
  • Ingestion points: search_web, read_url_content, and secure_crawl are used in SKILL.md and modes/research.md to fetch data.
  • Boundary markers: The skill synthesizes information into structured templates, though it does not explicitly use delimiters for external data.
  • Capability inventory: The skill can read workspace files and interacts with users via notify_user across all modes.
  • Sanitization: The skill includes specific instructions to sanitize content from deep crawls to prevent processing malicious payloads.
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection to initialize its state.
  • Evidence: SKILL.md uses the !cat command to read project-specific configuration and context files from the repository at startup.
  • Context: These operations are restricted to non-sensitive project artifacts and are used to provide the agent with necessary project orientation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — polymath