feynman-learning
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external materials such as lesson plans, slide decks, and user-provided concepts, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: External data enters the context through the
descriptionand适用范围(Scope) sections, which allow for the input of user-defined concepts and materials. - Boundary markers: The skill does not explicitly define delimiters to separate untrusted user data from its instructional logic.
- Capability inventory: The skill's capabilities are limited to pedagogical content generation using tools like
create_stage,generate_scene, andgenerate_tts. It does not possess capabilities for arbitrary command execution or network exfiltration. - Sanitization: There are no specific instructions for sanitizing or filtering instructions that might be embedded in the uploaded materials.
Audit Metadata