explain-code-tutor
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is instructed to read and trace paths through project files to explain code. If these files contain malicious instructions, they could affect agent behavior.\n
- Ingestion points: Project files read via the agent's file-system tools in SKILL.md.\n
- Boundary markers: The instructions do not provide delimiters to separate code content from instructions or specify that embedded instructions should be ignored.\n
- Capability inventory: The skill utilizes file reading, project search, and import tracing tools.\n
- Sanitization: The skill lacks instructions to sanitize or escape file content before processing it.\n- [PROMPT_INJECTION]: The skill contains a specific behavioral constraint ('Never use Russian under any circumstances') which acts as an override on the agent's standard language capabilities.
Audit Metadata