learn

Warn

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill metadata contains deceptive information regarding its provenance. The frontmatter claims the source is 'official' and attributes the author as 'DAIR.AI', contradicting the actual uploader context. This misrepresentation may lead users to inaccurately trust the skill's safety and origin.\n- [PROMPT_INJECTION]: The skill utilizes a tutoring workflow that involves reading external user data, creating a surface for indirect prompt injection.\n
  • Ingestion points: The agent is instructed to incorporate 'existing notes, files, chat history, or user-provided progress' when designing lessons (SKILL.md).\n
  • Boundary markers: There are no protective delimiters or instructions included to ensure the agent ignores malicious commands embedded within the learner's materials.\n
  • Capability inventory: The skill is designed to work with tools like claude-code and codex-cli which have access to the file system and system shell.\n
  • Sanitization: The workflow does not require any sanitization or validation of the content retrieved from external files or chat history before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 8, 2026, 06:40 AM
Security Audit — agent-trust-hub — learn