syllabus

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted syllabus documents (PDF, DOCX, images, or text) to extract topics and learning outcomes. * Ingestion points: Syllabus data provided by the user in Phase 0. * Boundary markers: No explicit delimiters are used to separate user-provided content from agent instructions. * Capability inventory: The skill has access to the Consensus search tool, file system write capabilities, and the ability to execute local scripts. * Sanitization: There is no evidence of sanitization for the extracted syllabus text.
  • [COMMAND_EXECUTION]: The skill executes multiple local scripts (topic_grouper.py, citation_tracker.py, discussion_question_validator.py, generate_reading_list.js) to perform data processing and document generation.
  • [EXTERNAL_DOWNLOADS]: The skill requires the 'docx' npm package. The documentation suggests that an installation via npm might be performed if the package is missing. The skill also retrieves academic paper data from the Consensus service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:42 PM
Security Audit — agent-trust-hub — syllabus