tutorial-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not contain any executable scripts, shell commands, or network operations. The instructions focus on content structure and educational methodology for transforming code into tutorials.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided code and technical topics as input for tutorial generation.
  • Ingestion points: The "Task-Specific Inputs" section identifies "Topic or Code" as the primary entry point for untrusted data.
  • Boundary markers: The skill does not define specific boundary markers or delimiters for the ingested content.
  • Capability inventory: The skill is limited to text generation and does not have access to tools, network operations, or file system write capabilities.
  • Sanitization: There are no explicit instructions to sanitize or validate the external content before processing.
  • Note: While the attack surface exists, the lack of dangerous capabilities or tool access makes this an informational finding with no direct security impact.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:20 PM
Security Audit — agent-trust-hub — tutorial-engineer