awe-wonder-experience-designer

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions are clearly defined and focus on educational design. There are no attempts to bypass safety filters or ignore system constraints.
  • [DATA_EXFILTRATION]: No network-enabled tools or commands are present. There is no access to environment variables, SSH keys, or other sensitive local files.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute external scripts or binaries.
  • [COMMAND_EXECUTION]: There are no shell commands or subprocess calls within the skill's logic.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: User-provided inputs like lesson_content and student_profiles are interpolated directly into the prompt in SKILL.md.
  • Boundary markers: The prompt uses bold headers to separate input fields but lacks explicit delimiters or instructions to ignore embedded commands within the user data.
  • Capability inventory: The skill performs only text generation; it lacks any tool access or execution capabilities.
  • Sanitization: No input validation or escaping is applied to the user-supplied fields.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 12:43 AM
Security Audit — agent-trust-hub — awe-wonder-experience-designer