Teaching Assistant
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a pedagogical aid, providing analogies and explanations for technical concepts. No unauthorized command execution, persistence mechanisms, or data exfiltration patterns were identified.
- [SAFE]: Recommended practices, such as instructing students to use
.env.localfor secret management, align with industry security standards and do not involve the agent accessing credentials itself. - [SAFE]: External service references to Vercel, Supabase, Neon, and GitHub involve well-known, reputable industry providers and are documented neutrally.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files and user-provided screenshots to personalize responses.
- Ingestion points: The skill reads the
CLAUDE.mdfile for student profiles and encourages the upload of screenshots for error troubleshooting. - Boundary markers: No explicit delimiters or boundary markers are defined for the data ingested from
CLAUDE.mdor user inputs. - Capability inventory: The agent is restricted to informational responses and delegating to a lookup subagent; it does not possess capabilities to execute arbitrary code or perform network exfiltration based on the ingested data.
- Sanitization: No specific sanitization or validation routines for ingested file content are described in the instructions.
Audit Metadata