teach
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified in the skill instructions.
- [EXTERNAL_DOWNLOADS]: Fetches syntax highlighting components from Cloudflare's well-known CDN for use in generated HTML lessons.
- [COMMAND_EXECUTION]: Suggests a scoped local server command for lesson previews using Python's built-in module, which is limited to the workspace directory.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests untrusted data from the web via search tools (Ingestion points:
RESOURCES.md). It lacks explicit boundary markers for this data in lessons but mandates a 'discover then verify' workflow (Sanitization: Verification). Its capabilities are limited to generating local files and suggesting user-executed commands (Capability inventory: File writing, local server suggestion).
Audit Metadata