start-learning
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill attempts to fetch a
ROADMAP.mdfile from the vendor's GitHub repository athttps://raw.githubusercontent.com/rohitg00/ai-engineering-from-scratch/main/ROADMAP.mdif a local version is not present. This is a documented resource provided by the skill author for curriculum metadata. - [INDIRECT_PROMPT_INJECTION]: The skill collects free-text responses from the user and fetches remote data, then writes them into a
LEARNING.mdfile. This file serves as the source of truth for subsequent skills (e.g.,learn), creating a potential pathway for malicious instructions to be persisted into the agent's long-term context. - Ingestion points: User responses to interview questions (Step 1) and the contents of the externally fetched
ROADMAP.md(Step 3). - Boundary markers: The skill uses Markdown headers and comments as delimiters in the generated file, but these are for structural organization rather than security sandboxing.
- Capability inventory: Includes reading and writing to the local file system and making network requests to GitHub.
- Sanitization: The instructions do not specify any validation, escaping, or sanitization of user input before it is written to the persistent state file.
Audit Metadata