teach

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from curated resources and user-maintained records, which could lead to indirect prompt injection if those sources contain malicious instructions.\n
  • Ingestion points: The agent is instructed to read content from RESOURCES.md (containing external URLs), MISSION.md, the ./learning-records/ directory, and files stored in a connected Obsidian or Knowledge Vault.\n
  • Boundary markers: The instructions do not define clear delimiters or specify that the agent should ignore instructions embedded within the ingested materials.\n
  • Capability inventory: The agent has the authority to write files to the local filesystem (HTML lessons and Markdown records) and execute shell commands to open these files for the user.\n
  • Sanitization: There are no mentioned protocols for sanitizing external content or validating the integrity of remote resources before synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 11:17 AM
Security Audit — agent-trust-hub — teach