teach

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process information from external resources to generate lessons, which introduces a surface for indirect prompt injection. 1. Ingestion points: The agent is instructed to fetch knowledge from external 'high-trust' resources tracked in RESOURCES.md. 2. Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within external data. 3. Capability inventory: The agent can write HTML files to the workspace and execute CLI commands. 4. Sanitization: The instructions do not specify any validation or sanitization for the external content before it is incorporated into lessons.
  • [COMMAND_EXECUTION]: The skill encourages the agent to use command-line interface tools to interact with the user's environment. Evidence: 'If possible, open the lesson file for the user by running a CLI command' in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:19 PM
Security Audit — agent-trust-hub — teach