teach
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external sources identified in RESOURCES.md and use this information to generate teaching materials. This creates a surface for indirect prompt injection if the external resources contain malicious instructions designed to influence the agent's behavior during the lesson generation process.\n
- Ingestion points: RESOURCES.md (external URLs), MISSION.md, and user inputs are used to populate the teaching workspace.\n
- Boundary markers: No specific delimiters or instructions to ignore embedded prompts in external content are provided in the skill definitions.\n
- Capability inventory: The agent writes HTML, MD, and CSS files, and is encouraged to execute CLI commands to open files.\n
- Sanitization: No explicit sanitization or validation of the content retrieved from external resources is mentioned.\n- [COMMAND_EXECUTION]: The instructions suggest that the agent should open the lesson file for the user by running a CLI command. Executing shell commands based on generated filenames (which may incorporate lesson titles) presents a potential risk if the input is not strictly controlled.\n- [DYNAMIC_EXECUTION]: The skill requires the agent to generate interactive HTML lessons that include scripts for quiz widgets, simulators, and diagram helpers. Generating and saving executable scripts to the local filesystem for later execution in a browser constitutes a dynamic code generation pattern.
Audit Metadata