course-guide

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches curriculum metadata and lesson content from a remote source. Specifically, it accesses the README.md, glossary, and lesson documentation from https://raw.githubusercontent.com/rohitg00/ai-engineering-from-scratch/main/. This behavior is consistent with the skill's purpose as a course navigator and utilizes the author's official repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external Markdown files (README.md, docs/en.md, terms.md) and JSON manifests to determine curriculum routing. While these are ingestion points for untrusted data, the skill's capabilities are limited to providing navigation advice and recommending follow-up commands, posing a low risk of malicious influence on the agent's behavior.
  • Ingestion points: Reads README.md, glossary/terms.md, and lesson documentation (docs/en.md) from the local filesystem or remote GitHub repository.
  • Boundary markers: None explicitly defined in the instructions for the data fetched.
  • Capability inventory: No file-write, network POST, or subprocess execution capabilities detected. The skill only performs HTTP GET requests for content.
  • Sanitization: No explicit sanitization of the fetched Markdown content is described, but the output is restricted to specific educational routing templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 09:02 AM
Security Audit — agent-trust-hub — course-guide