advisor
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of external and session-based data to define course objectives and justifications.
- Ingestion points: The agent reads content from
transcript.md,.audit/files, session records,.mentor/records,learner.md, and findings from the/researchsubagent. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat ingested data as distinct from instructions or to disregard embedded directives.
- Capability inventory: The agent has the authority to write
unit.mdfiles (defining outcomes for the teacher and auditor), updateroadmap.md, generateroadmap.html, and trigger additional research subagents. - Sanitization: The skill does not specify any validation, filtering, or escaping of the ingested content before it is used to generate the next planning documents.
Audit Metadata