summer-school-finder
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external university websites discovered at runtime, which introduces a surface for potential indirect prompt injection.
- Ingestion points: Data is ingested via the
tinyfish agent runcommand from university URLs identified during the search process in SKILL.md Step 3. - Boundary markers: The sub-agent prompt contains instructions for JSON formatting and specific extraction constraints, which acts as a rudimentary boundary, but the skill does not use formal prompt delimiters when aggregating the results for the user.
- Capability inventory: The skill has the capability to execute the
tinyfishCLI tool, write to the local filesystem for temporary storage (/tmp), and read those files for output. - Sanitization: No explicit validation or sanitization is applied to the scraped content before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
tinyfishCLI tool globally via NPM as a dependency for its core functionality. Documented neutrally as it is a legitimate requirement for the vendor-provided tool.
Audit Metadata