tutoring-session

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes untrusted user data (Learner Profile, topic descriptions, diagnostic results) and interpolates it into generated JSON and Markdown files.
  • Ingestion points: User input gathered in Step 1 (Learner Profile) and Step 2 (Specific Topic, Diagnostic Result, Success Criterion).
  • Boundary markers: None identified in the skill instructions to delimit untrusted content or warn the agent about embedded instructions.
  • Capability inventory: File writing operations to generate session-plan-tutoring.profile.json and schema validation using ajv (Step 8).
  • Sanitization: No explicit sanitization or filtering of the user-provided content is defined before file generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM