study-helper
Pass
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill describes a workflow that ingests data from external sources, creating an inherent risk for indirect prompt injection.
- Ingestion points: The skill uses
web_searchto find learning resources andread_fileto analyze study materials. - Boundary markers: There are no instructions or delimiters specified to differentiate external data from agent instructions or to ignore commands embedded in the retrieved content.
- Capability inventory: The skill integrates several tools including
web_search,note,calendar_event, andread_file. - Sanitization: The skill does not mention any sanitization, filtering, or validation of the content processed from external tools.
- [NO_CODE]: The skill consists exclusively of instructional markdown content and metadata. It does not package any scripts or binary files, which prevents direct code execution or traditional malware behavior.
Audit Metadata