skills/garethmanning/education-agent-skills/source-credibility-evaluation-protocol/Gen Agent Trust Hub
source-credibility-evaluation-protocol
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security risks were detected in the skill analysis. The skill is instructional in nature and does not request or utilize any system tools or network access.
- [PROMPT_INJECTION]: The skill uses detailed instructional prompting to define its persona as a digital literacy expert. No attempts to bypass safety filters, extract system prompts, or override agent constraints were found. Natural instructional language is used appropriately for the educational context.
- [DATA_EXFILTRATION]: The skill does not access sensitive file paths (e.g., credentials, SSH keys) nor does it perform any network operations. There are no hardcoded secrets or credentials.
- [REMOTE_CODE_EXECUTION]: There are no remote downloads, script executions, or package installations (npm/pip) present in the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for untrusted data which is interpolated into prompts.
- Ingestion points:
source_type,evaluation_context,student_level,specific_source,student_profiles,subject_area, andcommon_mistakesfields defined inSKILL.md. - Boundary markers: Absent; user-provided data is interpolated directly into the markdown prompt structure without explicit delimiters or escaping instructions.
- Capability inventory: None; the skill has no tool-calling capabilities, file system write access, or network execution power.
- Sanitization: Absent; no validation or filtering is performed on input variables.
- Analysis: Due to the lack of capabilities (no code execution or network access), the risk of indirect injection is negligible and is considered safe.
Audit Metadata