mindtickle-core-workflow-a

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for creating and updating training content that involves processing text inputs that could potentially contain malicious instructions.
  • Ingestion points: Data fields for course titles, module descriptions, and quiz questions in the code snippets within SKILL.md.
  • Boundary markers: There are no explicit delimiters or specific instructions to the agent to disregard instructions embedded within the training content being processed.
  • Capability inventory: The skill is configured with access to high-capability tools such as Bash (npm) and file system operations (Write, Edit).
  • Sanitization: The instructions do not include content validation, escaping, or sanitization protocols for the strings being integrated into the MindTickle platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 06:59 AM
Security Audit — agent-trust-hub — mindtickle-core-workflow-a