teach-impeccable
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted sources within the project codebase to update a persistent configuration file, creating a surface for potential injection.
- Ingestion points: The agent is instructed to read the project README, documentation, package.json, source code components, brand assets, and style guides.
- Boundary markers: The instructions lack specific boundary markers or requirements to ignore embedded instructions within the files being scanned.
- Capability inventory: The skill utilizes file system read access to explore the codebase and file system write access to modify or append to the
CLAUDE.mdfile in the project root. - Sanitization: There is no specified logic for sanitizing, escaping, or validating the content extracted from the codebase before it is written to the persistent configuration file.
Audit Metadata