NYC

pymoo

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOW
Full Analysis
  • PROMPT_INJECTION (SAFE): The instruction files and documentation contain no patterns for overriding agent behavior or bypassing safety filters. All instructions are strictly related to library usage and optimization concepts.\n- DATA_EXFILTRATION (SAFE): No hardcoded credentials, sensitive file path access (e.g., SSH keys, env files), or unauthorized network operations were detected in the provided scripts.\n- EXTERNAL_DOWNLOADS (LOW): The visualization documentation mentions a requirement for 'ffmpeg' to export videos, but the skill does not attempt to download, install, or execute any external binaries automatically.\n- REMOTE_CODE_EXECUTION (SAFE): The scripts use standard Python imports and library calls. There is no evidence of remote script execution (curl|bash) or runtime code injection from untrusted sources.\n- INDIRECT_PROMPT_INJECTION (SAFE): The skill operates on defined optimization problems (benchmarks like ZDT1, DTLZ2) or locally defined classes. There are no untrusted data ingestion points (APIs, web scraping, or file reads) that could be used for injection attacks. (Ingestion points: None; Boundary markers: N/A; Capability inventory: No unsafe subprocess/exec calls; Sanitization: N/A).
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 10:57 AM