teach
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on reading user-editable files to determine teaching outcomes and lesson content, creating a potential surface for indirect instruction injection.\n
- Ingestion points: The agent reads from MISSION.md, RESOURCES.md, learning-records/, and NOTES.md to select lessons and retrieve educational information.\n
- Boundary markers: The instructions do not define delimiters or protective prompts to distinguish between data and instructions within the ingested files.\n
- Capability inventory: The skill is capable of reading and writing Markdown and HTML files within the local workspace.\n
- Sanitization: No sanitization or validation of the content within these workspace files is described, though it instructs the agent to prefer high-trust sources.\n- [NO_CODE]: The skill consists entirely of Markdown instructions and format templates. No executable scripts, binaries, or configuration files were detected in the provided source files.
Audit Metadata