learn-anything

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing user-provided external content, which presents a surface for indirect prompt injection.
  • Ingestion points: In SKILL.md, the instructions command the agent to "Read any source, file, or code the user named" to support the learning session.
  • Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) or provide warnings to the model to ignore instructions potentially embedded within the ingested source files.
  • Capability inventory: The skill utilizes user interaction tools (request_user_input, AskUserQuestion, or question) and implies the use of the agent's file system or code reading capabilities to ingest the specified sources.
  • Sanitization: There is no evidence of content sanitization or filtering applied to the external files before they are processed in the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:22 PM
Security Audit — agent-trust-hub — learn-anything