polyglot-learning-strategies-expert

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions in modules/research-checklist.md define a workflow where the agent performs web research and incorporates findings into its core modules. This creates a surface for indirect prompt injection because the agent is instructed to process and "distill" content from external, untrusted sources which may contain instructions designed to override the agent's behavior.
  • Ingestion points: External web sources, official documentation, expert articles, Wikipedia, and ArXiv as specified in the modules/research-checklist.md workflow.
  • Boundary markers: The skill does not define any delimiters or explicit instructions to treat ingested content as data rather than instructions.
  • Capability inventory: The skill uses web research tools and adn_skills for distillation; it also contains instructions for the agent to modify its own local files (modules/core-guidance.md and metadata) to store research results.
  • Sanitization: There are no verification, validation, or sanitization steps described to ensure that the content being "distilled" and written back to the skill files is safe or free from embedded commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 05:38 PM
Security Audit — agent-trust-hub — polyglot-learning-strategies-expert