learn
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch information from external web resources and communities to generate educational lessons, records, and glossaries. This creates a potential vector for indirect prompt injection if the external data contains instructions designed to manipulate the agent's behavior during content generation.
- Ingestion points: External URLs and community feedback ingested into
RESOURCES.MDand used to populate lessons. - Boundary markers: Absent. The skill does not provide instructions to delimit untrusted external content or to ignore embedded commands within the fetched data.
- Capability inventory: The agent is directed to create and write various files in the
docs/learn/directory, including Markdown files and HTML files containing generated scripts for widgets or simulators. - Sanitization: Absent. There are no requirements for the agent to sanitize, escape, or validate the content retrieved from external sources before it is interpolated into the workspace files.
Audit Metadata