teach-impeccable

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted sources within the local codebase and incorporates it into persistent instruction files, creating a surface for indirect prompt injection.
  • Ingestion points: The skill scans project files including README.md, package.json, source components, and brand documentation to infer design patterns.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from obeying malicious instructions that might be embedded within the analyzed project files.
  • Capability inventory: The skill utilizes file-reading capabilities to scan the codebase and file-writing capabilities to update .impeccable.md and .github/copilot-instructions.md.
  • Sanitization: The skill lacks a sanitization or validation step to filter out malicious content or instruction overrides from the files it reads before persisting them into the agent's configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — teach-impeccable