study-strategy-selector

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is comprised of natural language instructions with no executable scripts, binaries, or automated tools.
  • [PROMPT_INJECTION]: The skill effectively addresses the attack surface of indirect prompt injection by instructing the agent to treat external inputs as untrusted and prohibiting them from authorizing commands or access.
  • Ingestion points: User-provided notes, syllabi, and student profiles referenced in SKILL.md.
  • Boundary markers: Explicitly present in the 'Safety and accuracy boundary' section.
  • Capability inventory: None detected; no tools or file/network capabilities are defined.
  • Sanitization: Instructions direct the agent to filter and ignore embedded directives.
  • [DATA_EXFILTRATION]: The instructions establish clear prohibitions against unauthorized contact with external services and secret access, ensuring data remains within the intended context.
  • [EXTERNAL_DOWNLOADS]: All external URLs are documentation-based (GitHub attribution and Creative Commons license links) and do not involve package installation or remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:07 AM
Security Audit — agent-trust-hub — study-strategy-selector