grounding
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes specific defensive instructions to mitigate indirect prompt injection from course content. Evidence chain: (1) Ingestion points:
search_dometrain,search_code, andget_lessontools inSKILL.md. (2) Boundary markers: Explicit 'untrusted reference data' warnings are present in the 'Purpose' section. (3) Capability inventory: Tool access is limited to the defined MCP functions, with no dangerous shell or file-write capabilities. (4) Sanitization: The skill uses instructional constraints to ensure the agent ignores any directives embedded in returned lesson text.\n- [EXTERNAL_DOWNLOADS]: The skill references official resources fromdometrain.comand its public repositorygithub.com/Dometrain/mcp. These are well-known services and the downloads/references are appropriate for the skill's purpose.\n- [COMMAND_EXECUTION]: No dangerous shell commands, scripts, or privilege escalation patterns were detected. The skill logic is confined to standard metadata and instructional guidance.
Audit Metadata