learn-anything
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides coaching instructions and interaction patterns for a tutoring agent.
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by allowing the agent to read user-specified files or code. 1. Ingestion points: Instructions in SKILL.md to read any source, file, or code the user named. 2. Boundary markers: Absent; the skill does not specify delimiters or instructions to ignore embedded commands. 3. Capability inventory: Agent capabilities are limited to learner-facing question tools (e.g., AskQuestion, AskUserQuestion) and file reading; it does not request tools for subprocess execution, network access, or file modification. 4. Sanitization: Absent; the skill does not outline validation or filtering for external content processed during retrieval.
Audit Metadata