glossary-generator
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from
docs/learning-graph/02-concept-list-v1.md,docs/course-description.md, and all files matchingdocs/**/*.md. This creates a vulnerability where malicious instructions embedded in these documentation files could influence the agent's behavior. - Ingestion points:
SKILL.mddirects the agent to read the concept list and all markdown files within thedocs/directory to understand course context. - Boundary markers: The skill does not provide the agent with explicit instructions to use delimiters or to disregard instructions found within the ingested files.
- Capability inventory: The skill is authorized to perform multiple file-write operations, including creating the glossary, generating reports, and modifying the project's
mkdocs.ymlconfiguration file. - Sanitization: There are no prescribed methods for sanitizing or validating the input data before it is interpolated into the generated output or used to update existing project configurations.
Audit Metadata