worldmat-tidar
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): The skill references and imports non-standard Python packages
openai_acsetandgay. These are not from the list of trusted GitHub repositories or organizations. - COMMAND_EXECUTION (LOW): The documentation instructs the user to execute a local Python script
worldmat.pyvia CLI (python worldmat.py), which executes code on the host machine. - INDIRECT_PROMPT_INJECTION (LOW): The skill identifies a surface where untrusted conversation data is processed through the matrix. Ingestion points:
conv_fingerprintand message-to-cell mapping inSKILL.md. Boundary markers: None found. Capability inventory: CLI execution ofworldmat.py. Sanitization: None found in the provided documentation.
Audit Metadata