mindtickle-core-workflow-a
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for creating and updating training content that involves processing text inputs that could potentially contain malicious instructions.
- Ingestion points: Data fields for course titles, module descriptions, and quiz questions in the code snippets within
SKILL.md. - Boundary markers: There are no explicit delimiters or specific instructions to the agent to disregard instructions embedded within the training content being processed.
- Capability inventory: The skill is configured with access to high-capability tools such as
Bash(npm) and file system operations (Write,Edit). - Sanitization: The instructions do not include content validation, escaping, or sanitization protocols for the strings being integrated into the MindTickle platform.
Audit Metadata