teach

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes dynamic context injection (the ! syntax) in the pre-computed context section of SKILL.md to list existing workspaces. These operations are limited to path normalization and directory listing using standard system utilities, with no injection of untrusted user input.
  • [SAFE]: The skill processes repository files and external documentation, creating an indirect prompt injection surface. This is the primary intended function of the skill and is mitigated by instructions to prioritize high-trust sources, mask secrets in generated HTML lessons, and use local state for persistence.
  • [SAFE]: Path resolution rules for workspace management include explicit mitigations against directory traversal by stripping special characters (e.g., '/', '', '..') from topic and concept slugs.
  • [SAFE]: All identified external references are directed toward the author's official documentation or well-known services, posing no threat of unauthorized remote code execution or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:56 PM
Security Audit — agent-trust-hub — teach