teach-impeccable

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted sources within the project codebase to update a persistent configuration file, creating a surface for potential injection.
  • Ingestion points: The agent is instructed to read the project README, documentation, package.json, source code components, brand assets, and style guides.
  • Boundary markers: The instructions lack specific boundary markers or requirements to ignore embedded instructions within the files being scanned.
  • Capability inventory: The skill utilizes file system read access to explore the codebase and file system write access to modify or append to the CLAUDE.md file in the project root.
  • Sanitization: There is no specified logic for sanitizing, escaping, or validating the content extracted from the codebase before it is written to the persistent configuration file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 04:00 PM
Security Audit — agent-trust-hub — teach-impeccable