Add School Calendar

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands, including curl for downloading PDF documents and python3 for running local utility scripts like scrape_board_calendar.py and validate_calendar.py to process calendar data.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external web sources and downloads PDF files from school board and private school websites to populate its internal reference library.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external sources including web search results, HTML tables, and PDF contents. This ingestion point creates a potential surface for indirect prompt injection where malicious instructions could be embedded in school documents. The skill lacks explicit boundary markers or sanitization logic in its instructions, though its structured extraction workflow naturally limits the impact of such instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 12:01 AM
Security Audit — agent-trust-hub — Add School Calendar