school-ops

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses explicit behavioral overrides, such as 'Do NOT ask the user questions', and a series of negative constraints ('DO NOT' section) to force the agent into a specific persona. It also ingests untrusted codebase files without protective boundary markers or sanitization, creating a surface for indirect prompt injection. (Ingestion points: actual codebase, package manifests; Boundary markers: absent; Capability inventory: file-read, file-write; Sanitization: absent).\n- [DATA_EXFILTRATION]: The instructions direct the agent to access and analyze highly sensitive data categories, including staff salaries, student demographics, and IEP (special education) service details, which are protected under privacy laws like FERPA.\n- [COMMAND_EXECUTION]: The 'SELF-EVOLUTION TELEMETRY' section instructs the agent to search for and write execution metadata to a specific path in the user's home directory (~/.claude/projects/skill-telemetry.md), which represents file system interaction outside the standard project workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — school-ops