learn-to-agents
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill's instructions for identifying reusable learnings include a specific prohibition against adding secrets, private tokens, credentials, or sensitive data to the documentation files.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection as it reads project-specific context to update guidance files for future agents.
- Ingestion points: User requests, outcome logs, changed files, and existing instruction files (SKILL.md).
- Boundary markers: The skill does not define explicit delimiters or boundary markers for the external data being processed.
- Capability inventory: The agent has the ability to read and write files within the repository scope, specifically targeting AGENTS.md files.
- Sanitization: The skill contains specific operational guidelines to filter out generic, temporary, or sensitive information during the documentation process.
Audit Metadata