mathodology-dev-test-release

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script scripts/validate_repo.py contains a bootstrap command that fetches an update script from raw.githubusercontent.com/sweetcornna/mathodology. This is a vendor-owned resource used for project maintenance.
  • [REMOTE_CODE_EXECUTION]: The skill executes the downloaded updater script using python3 and triggers its self-test mode. It also includes instructions for using uvx free-search-mcp to manage external search capabilities.
  • [COMMAND_EXECUTION]: The validation script utilizes subprocess.check_output to run git ls-files for whitelist verification and uses subprocess.run to execute the updater script during self-testing.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill checks for the absence of secrets in final packages and manages a local cache directory for search results ($HOME/.cache/search-mcp/downloads). No evidence of sensitive data exfiltration to unauthorized domains was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:40 PM
Security Audit — agent-trust-hub — mathodology-dev-test-release