study-strategy-selector
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is comprised of natural language instructions with no executable scripts, binaries, or automated tools.
- [PROMPT_INJECTION]: The skill effectively addresses the attack surface of indirect prompt injection by instructing the agent to treat external inputs as untrusted and prohibiting them from authorizing commands or access.
- Ingestion points: User-provided notes, syllabi, and student profiles referenced in SKILL.md.
- Boundary markers: Explicitly present in the 'Safety and accuracy boundary' section.
- Capability inventory: None detected; no tools or file/network capabilities are defined.
- Sanitization: Instructions direct the agent to filter and ignore embedded directives.
- [DATA_EXFILTRATION]: The instructions establish clear prohibitions against unauthorized contact with external services and secret access, ensuring data remains within the intended context.
- [EXTERNAL_DOWNLOADS]: All external URLs are documentation-based (GitHub attribution and Creative Commons license links) and do not involve package installation or remote code execution.
Audit Metadata