teach
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data which could lead to indirect prompt injection if the source materials contain malicious instructions.
- Ingestion points: The agent reads from MISSION.md, RESOURCES.md, and NOTES.md (found in the workspace root), which are populated based on user input and descriptions of external resources.
- Boundary markers: The provided formats in MISSION-FORMAT.md and RESOURCES-FORMAT.md do not specify the use of delimiters or instructions to ignore embedded content when interpolating this data into lessons.
- Capability inventory: The agent writes files (Markdown, HTML, and assets in ./assets/) and is instructed in SKILL.md to run CLI commands to open these files.
- Sanitization: There are no instructions for sanitizing or escaping content from resources or the mission statement before embedding it in HTML lessons.
- [DYNAMIC_EXECUTION]: The skill generates and potentially triggers the execution of scripts within HTML files.
- Evidence: SKILL.md specifies that lessons are self-contained HTML files stored in ./lessons/ which include components like 'quiz widgets, simulators, diagram helpers' from the ./assets/ directory.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to facilitate the user's interaction with generated content.
- Evidence: SKILL.md contains the instruction: 'If possible, open the lesson file for the user by running a CLI command.' This leads to the execution of the generated HTML/JavaScript in the user's local browser environment.
Audit Metadata