skills/joseph-lozano/skills/teach/Gen Agent Trust Hub

teach

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill maintains a stateful workspace by reading and writing files such as MISSION.md, RESOURCES.md, and learning records. Because these files can be populated with data from external, untrusted resources discovered by the agent, they represent a surface for indirect prompt injection.\n
  • Ingestion points: MISSION.md, RESOURCES.md, and files in the ./learning-records/ directory.\n
  • Boundary markers: No delimiters or ignore instructions are specified for these inputs.\n
  • Capability inventory: The agent has the ability to write files and execute CLI commands.\n
  • Sanitization: No sanitization or validation logic is defined for data imported from external resources.\n- [COMMAND_EXECUTION]: The agent is explicitly instructed to open the lesson file for the user by running a CLI command, which prompts the use of shell execution capabilities to interact with the host environment.\n- [DYNAMIC_EXECUTION]: The skill generates reusable components and interactive lessons (HTML, stylesheets, quiz widgets, simulators) at runtime in the ./assets/ and ./lessons/ directories based on the teaching context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:27 AM
Security Audit — agent-trust-hub — teach