School Selection
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill performs legitimate educational consultation tasks including searching for university programs and matching them to a user's academic profile. No patterns of data exfiltration, credential theft, or unauthorized persistence were found.
- [COMMAND_EXECUTION]: The skill executes the
datecommand to calculate current application windows and timelines. This is a functional requirement for academic planning and does not represent a security risk. - [PROMPT_INJECTION]: The skill processes untrusted data from web search results to identify program requirements (Indirect Prompt Injection surface).
- Ingestion points: External program data retrieved via the
WebSearchtool. - Boundary markers: Absent.
- Capability inventory: Limited to shell execution of
dateand theWebSearchtool. - Sanitization: Absent.
- Although the surface exists, it is consistent with the primary purpose of the skill and the risk is mitigated by standard agent safety protocols.
Audit Metadata