language-demand-analyser
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates several user-provided input fields directly into the primary prompt without using structural delimiters or instructions to ignore embedded commands, creating a surface for indirect prompt injection.
- Ingestion points:
task_description,student_level,subject_area,language_proficiency,student_profiles,task_materials, andprior_language_instructionfields inSKILL.md. - Boundary markers: Absent. Input data is concatenated with bold labels but lacks clear encapsulation such as XML tags or triple quotes.
- Capability inventory: None. The skill does not have access to tools, network operations, or file system modifications.
- Sanitization: Absent. There is no evidence of input filtering or validation before the data is processed by the model.
Audit Metadata