course-visualize
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE]: The skill constructs file system paths using a user-provided
course-slugargument without explicit validation markers in the instruction set. - Evidence: The paths
docs/instructional-design/courses/{slug}/course.jsonanddocs/instructional-design/courses/{slug}/course.htmlrely on the{slug}variable. - Risk: An unsanitized input could potentially be used for path traversal, although the impact is limited by the skill's specific directory scope.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from a JSON file to generate an HTML visualization, creating a vulnerability surface for indirect injection.
- Ingestion points: The file
docs/instructional-design/courses/{slug}/course.json(SKILL.md). - Boundary markers: None present in the instructions to delimit the data for the sub-agent.
- Capability inventory: The skill utilizes an internal agent to read local files and write generated HTML files back to the filesystem.
- Sanitization: No sanitization or validation of the JSON content is mentioned before it is passed to the
course-visualizer.mdagent or rendered into HTML.
Audit Metadata