teach
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from the user's environment to provide explanations, which creates a vulnerability surface for indirect prompt injection.
- Ingestion points: In
SKILL.md, step 2 instructs the agent to open and read the actual code, system, or concept being taught from the local environment. - Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) or explicit 'ignore embedded instructions' warnings when the agent processes this external content.
- Capability inventory: The skill utilizes file-reading capabilities to ingest material and has the ability to interact with a 'vault' or 'second brain' for reading and writing, though it includes a safeguard to 'Ask before you write.'
- Sanitization: There are no defined procedures for sanitizing, escaping, or filtering the ingested content before the agent processes it for the explanation.
Audit Metadata