education-tutor-research
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it is designed to ingest and process untrusted data from arbitrary external websites via WebSearch and WebFetch tools. Ingestion points: Untrusted external web content enters the agent context during the research phase. Boundary markers: The instructions lack the use of delimiters or explicit 'ignore' warnings for the content fetched from the web. Capability inventory: The skill uses WebSearch, WebFetch, and can read local filesystem data to analyze code patterns. Sanitization: No specific sanitization, filtering, or validation of the fetched external content is described before it is integrated into the final output.
Audit Metadata