new-course
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
ajvCLI tool to validate generated JSON files against a schema. This is a standard software development practice for ensuring data integrity. - [DATA_EXPOSURE]: The skill creates and writes to a structured directory (
docs/instructional-design/courses/) to store course materials. It does not attempt to access sensitive system directories or credentials. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user input and arguments to populate course metadata. While there is a potential surface for indirect injection via these inputs, the skill maintains a strict step-by-step workflow with approval gates, which significantly limits the impact of such vectors.
- [SAFE]: The skill references internal agent scripts and methodology files located within the agent's plugin root, which is expected behavior for a complex modular skill.
Audit Metadata