e-learning-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of pedagogical guidelines and well-structured Python boilerplate for learning management systems, assessments, and analytics. No evidence of prompt injection, data exfiltration, or unauthorized command execution was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture handles external data through student profiles and assignment submissions, which is a standard requirement for e-learning platforms. While this represents a theoretical ingestion surface for indirect prompt injection, it is considered safe within the context of the skill's primary purpose.
  • Ingestion points: Data enters the system via Student (name, email) and Submission (content, attachments) dataclasses in references/EXAMPLES.md.
  • Boundary markers: None defined in the reference code.
  • Capability inventory: The skill uses Read, Write, and WebSearch tools; no dangerous shell or system capabilities are utilized in the examples.
  • Sanitization: Not present in the provided logical data structures.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — e-learning-expert