new-course

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the ajv CLI tool to validate generated JSON files against a schema. This is a standard software development practice for ensuring data integrity.
  • [DATA_EXPOSURE]: The skill creates and writes to a structured directory (docs/instructional-design/courses/) to store course materials. It does not attempt to access sensitive system directories or credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input and arguments to populate course metadata. While there is a potential surface for indirect injection via these inputs, the skill maintains a strict step-by-step workflow with approval gates, which significantly limits the impact of such vectors.
  • [SAFE]: The skill references internal agent scripts and methodology files located within the agent's plugin root, which is expected behavior for a complex modular skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM