tutoring-session
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes untrusted user data (Learner Profile, topic descriptions, diagnostic results) and interpolates it into generated JSON and Markdown files.
- Ingestion points: User input gathered in Step 1 (Learner Profile) and Step 2 (Specific Topic, Diagnostic Result, Success Criterion).
- Boundary markers: None identified in the skill instructions to delimit untrusted content or warn the agent about embedded instructions.
- Capability inventory: File writing operations to generate session-plan-tutoring.profile.json and schema validation using ajv (Step 8).
- Sanitization: No explicit sanitization or filtering of the user-provided content is defined before file generation.
Audit Metadata