course-builder

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted user-provided content and existing files to generate course materials, which constitutes an indirect prompt injection surface.
  • Ingestion points: Phase 1 extracts user input and copies provided files into the project workspace for processing by the agent team.
  • Boundary markers: The instructions do not define clear boundaries or 'ignore' directives to isolate user data from system prompts during curriculum generation.
  • Capability inventory: The workflow allows agents to write files to the local directory and send messages to other agents to execute tasks.
  • Sanitization: The skill lacks mechanisms to sanitize or validate the content of the files provided by the user before they are processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:06 AM
Security Audit — agent-trust-hub — course-builder