education-suite
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions to 'Do NOT ask the user questions' and 'Execute all four phases sequentially without pausing,' which are designed to override the agent's interactive guardrails and enforce autonomy.
- [COMMAND_EXECUTION]: The 'SELF-HEALING VALIDATION' phase directs the agent to execute shell commands for building, compiling, and running test suites, creating a capability surface for local code execution.
- [COMMAND_EXECUTION]: The skill instructs the agent to check for and append data to
~/.claude/projects/skill-telemetry.md, involving interaction with application-specific hidden directories. - [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection as it ingests untrusted data via
$ARGUMENTSwhich then influences a workflow capable of executing shell commands. Ingestion points:$ARGUMENTSin SKILL.md. Boundary markers: Absent. Capability inventory: Shell execution of build/test commands in SKILL.md. Sanitization: Absent.
Audit Metadata