course-guide
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches curriculum metadata and lesson content from a remote source. Specifically, it accesses the
README.md, glossary, and lesson documentation fromhttps://raw.githubusercontent.com/rohitg00/ai-engineering-from-scratch/main/. This behavior is consistent with the skill's purpose as a course navigator and utilizes the author's official repository. - [INDIRECT_PROMPT_INJECTION]: The skill processes external Markdown files (
README.md,docs/en.md,terms.md) and JSON manifests to determine curriculum routing. While these are ingestion points for untrusted data, the skill's capabilities are limited to providing navigation advice and recommending follow-up commands, posing a low risk of malicious influence on the agent's behavior. - Ingestion points: Reads
README.md,glossary/terms.md, and lesson documentation (docs/en.md) from the local filesystem or remote GitHub repository. - Boundary markers: None explicitly defined in the instructions for the data fetched.
- Capability inventory: No file-write, network POST, or subprocess execution capabilities detected. The skill only performs HTTP GET requests for content.
- Sanitization: No explicit sanitization of the fetched Markdown content is described, but the output is restricted to specific educational routing templates.
Audit Metadata