ship-learn-next

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to read and analyze untrusted external content provided by the user, such as YouTube transcripts, notes, and articles. This creates a surface for indirect prompt injection attacks where malicious instructions hidden in the input content could influence the agent's behavior.
  • Ingestion points: The Read tool is used in SKILL.md (Step 1) to ingest file content provided by the user.
  • Boundary markers: The instructions do not define clear delimiters or specific guidance for the agent to treat the ingested content as data only and to ignore any embedded instructions.
  • Capability inventory: The skill utilizes the Read and Write tools, allowing it to interpret external data and subsequently create or modify files on the local filesystem.
  • Sanitization: There is no specified mechanism for sanitizing or filtering the content read from external files before it is used to generate the output plan.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — ship-learn-next