teach
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process information from external resources to generate lessons, which introduces a surface for indirect prompt injection. 1. Ingestion points: The agent is instructed to fetch knowledge from external 'high-trust' resources tracked in RESOURCES.md. 2. Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within external data. 3. Capability inventory: The agent can write HTML files to the workspace and execute CLI commands. 4. Sanitization: The instructions do not specify any validation or sanitization for the external content before it is incorporated into lessons.
- [COMMAND_EXECUTION]: The skill encourages the agent to use command-line interface tools to interact with the user's environment. Evidence: 'If possible, open the lesson file for the user by running a CLI command' in SKILL.md.
Audit Metadata