orbitant-new-learning

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes local files containing user profile data and lesson archives to tailor learning suggestions. While this creates a surface for indirect prompt injection if these files were to contain untrusted content, the behavior is functional and standard for this skill. \n- Ingestion points: ~/.claude/learning/profile.md, ~/.claude/learning/lessons/archive/, and ~/.claude/learning/backlog.md. \n- Boundary markers: None identified in the prompt instructions. \n- Capability inventory: File reading (profile, archives, insights), file writing (backlog.md), and web search functionality. \n- Sanitization: Content is processed without explicit sanitization steps. \n- [DATA_EXFILTRATION]: The skill accesses application-specific files to inform web searches for learning resources. This access is limited to the skill's local data directory and does not involve sensitive system credentials or files like SSH keys or environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 11:50 PM
Security Audit — agent-trust-hub — orbitant-new-learning