teach
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data to populate its knowledge base.
- Ingestion points: The agent is instructed to find high-quality resources and record them in
RESOURCES.md, which are then used to generate lessons inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or boundary markers when processing external content.
- Capability inventory: The skill utilizes
Read,Write, andEdittools and is encouraged to use CLI commands to open files. - Sanitization: No explicit sanitization or validation steps are defined for content retrieved from external URLs or communities.
- [COMMAND_EXECUTION]: The instructions contain a directive to use the command line for file operations.
- Evidence: The skill states: "If possible, open the lesson file for the user by running a CLI command." This creates a potential vector for command injection if the filename or the environment allows for arbitrary command execution.
- [EXTERNAL_DOWNLOADS]: The skill metadata and body refer to an upstream source for its logic.
- Evidence: The skill is imported from
mattpocock/skillsand mentions a validator script at.agent-skills/skill-standardization/scripts/validate_skill.sh.
Audit Metadata