teach
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to open generated HTML lesson files using a system CLI command. This is a functional requirement to display the content to the user and uses standard platform capabilities for file handling.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process content from external sources to generate lessons. \n
- Ingestion points: External resources and URLs defined in RESOURCES.md. \n
- Boundary markers: The framework does not explicitly mandate boundary markers or delimiters when interpolating external content into generated lessons. \n
- Capability inventory: The skill has permissions to write files to the local workspace and trigger CLI commands to open files. \n
- Sanitization: The skill relies on instructions for the agent to prioritize high-trust, primary sources as a method of minimizing risk from potentially malicious external data.
Audit Metadata