course-builder
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted user-provided content and existing files to generate course materials, which constitutes an indirect prompt injection surface.
- Ingestion points: Phase 1 extracts user input and copies provided files into the project workspace for processing by the agent team.
- Boundary markers: The instructions do not define clear boundaries or 'ignore' directives to isolate user data from system prompts during curriculum generation.
- Capability inventory: The workflow allows agents to write files to the local directory and send messages to other agents to execute tasks.
- Sanitization: The skill lacks mechanisms to sanitize or validate the content of the files provided by the user before they are processed by the LLM.
Audit Metadata