learn

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute code chunks sourced from the curriculum (Step 2.3) to provide real output during lessons if a runtime is available.- [EXTERNAL_DOWNLOADS]: Lesson content, including markdown guides and JSON-formatted quizzes, is fetched from the rohitg00/ai-engineering-from-scratch repository on GitHub.- [DYNAMIC_EXECUTION]: The teaching process involves runtime execution of code snippets defined in the fetched curriculum to demonstrate core concepts.- [INDIRECT_PROMPT_INJECTION]: The skill consumes external data that could be manipulated to influence agent behavior.
  • Ingestion points: local LEARNING.md, remote en.md, and remote quiz.json.
  • Boundary markers: None; the agent is instructed to frame the problem and explain concepts directly from these files.
  • Capability inventory: Can write to the local file system (updating progress logs) and execute shell commands (running lesson code).
  • Sanitization: No evidence of sanitization or safety filtering for the remote curriculum content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 09:03 AM
Security Audit — agent-trust-hub — learn