ai-expertise-interrogation-designer
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No executable code, scripts, or binaries are included in the skill. The content consists entirely of Markdown instructions and prompt templates for an LLM.
- [SAFE]: No evidence of data exfiltration, credential harvesting, or unauthorized network access was found. The skill does not utilize any tools or commands that interact with the file system or external APIs.
- [PROMPT_INJECTION]: The skill prompt interpolates user-controlled variables (e.g., student_expertise_domain) without boundary markers or sanitization. 1. Ingestion points: SKILL.md (Prompt section); 2. Boundary markers: Absent; 3. Capability inventory: No subprocess calls, file-writes, or network operations detected; 4. Sanitization: Absent. While this presents an indirect prompt injection surface, the total lack of capabilities makes the risk negligible.
Audit Metadata