learning-design-review
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external content, creating a vulnerability surface where embedded malicious instructions could potentially influence agent behavior. Ingestion points: Educational content is gathered from user-provided file paths, URLs, or pasted text (SKILL.md, Step 1). Boundary markers: The instructions do not define explicit delimiters or 'ignore instructions' warnings to distinguish user-provided content from agent instructions. Capability inventory: The skill is instructed to read local YAML configuration files and process external data sources (SKILL.md, Step 2). Sanitization: There is no evidence of sanitization, escaping, or filtering applied to the external content before it is processed by the agent.
Audit Metadata