open-lesson

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations via curl to https://www.openlesson.academy to manage tutoring workflows and learning plans. This activity is restricted to the official service domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data returned by the openLesson API, specifically transcripts and follow-up questions. While this constitutes an ingestion point for external data, it is necessary for the skill's tutoring function.
  • Ingestion points: API response fields transcript and followUpQuestion from the /api/agent/session/analyze endpoint described in SKILL.md.
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: Uses Bash (curl) for all network communication.
  • Sanitization: None specified in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:46 PM
Security Audit — agent-trust-hub — open-lesson