skills/hk-hub/agentskills/teach/Gen Agent Trust Hub

teach

Warn

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md explicitly direct the agent to "open the lesson file for the user by running a CLI command." This pattern encourages shell interaction for file opening (e.g., using open or start), which represents a security risk if the file paths or command strings are not strictly controlled.
  • [DYNAMIC_EXECUTION]: The skill framework involves generating and storing interactive components such as "quiz widgets, simulators, and diagram helpers" as HTML/JavaScript in the ./assets/ directory. These files are subsequently linked into lessons and opened in the user's environment, creating a path for the execution of agent-generated code.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on discovering and ingesting external data from the internet to populate RESOURCES.md and generate lessons. This creates a surface where malicious instructions embedded in external web pages could influence the agent's logic or be transitively executed through generated HTML lessons.
  • Ingestion points: RESOURCES.md, MISSION.md, and content fetched from external URLs discovered during the teaching process.
  • Boundary markers: The provided templates in MISSION-FORMAT.md and RESOURCES-FORMAT.md do not include explicit delimiters or instructions to ignore embedded commands within the ingested data.
  • Capability inventory: The skill possesses the ability to write arbitrary files (.md, .html, .js) and execute CLI commands to open those files.
  • Sanitization: There are no instructions for sanitizing or escaping content retrieved from external resources before it is interpolated into the workspace files or lessons.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — teach