skills/julianromli/faiz-skills/teach/Gen Agent Trust Hub

teach

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it aggregates data from external sources and user records to generate educational lessons. Ingestion points: The agent reads MISSION.md, learning-records/*.md, and external resources linked in RESOURCES.md. Boundary markers: No specific delimiters are mandated to separate ingested data from agent instructions. Capability inventory: The agent has filesystem write permissions to ./lessons/, ./assets/, and ./reference/ directories, and is instructed to execute CLI commands to open files. Sanitization: No explicit content sanitization instructions are provided, relying on the agent's internal safety filters and the directive to use high-trust resources.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute CLI commands (e.g., 'open') to display generated HTML lesson files to the user. This is a legitimate functional requirement for the skill's operation.
  • [EXTERNAL_DOWNLOADS]: The agent is tasked with researching and providing links to external high-quality resources and communities (e.g., subreddits, forums) to support the user's learning mission.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:49 AM
Security Audit — agent-trust-hub — teach