summer-school-finder

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external university websites discovered at runtime, which introduces a surface for potential indirect prompt injection.
  • Ingestion points: Data is ingested via the tinyfish agent run command from university URLs identified during the search process in SKILL.md Step 3.
  • Boundary markers: The sub-agent prompt contains instructions for JSON formatting and specific extraction constraints, which acts as a rudimentary boundary, but the skill does not use formal prompt delimiters when aggregating the results for the user.
  • Capability inventory: The skill has the capability to execute the tinyfish CLI tool, write to the local filesystem for temporary storage (/tmp), and read those files for output.
  • Sanitization: No explicit validation or sanitization is applied to the scraped content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the tinyfish CLI tool globally via NPM as a dependency for its core functionality. Documented neutrally as it is a legitimate requirement for the vendor-provided tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:04 AM
Security Audit — agent-trust-hub — summer-school-finder