teaching-reflector

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes raw, untrusted student evaluation comments, which creates a surface for indirect prompt injection if malicious instructions are embedded within the feedback. * Ingestion points: Raw comments and scalar exports are collected during the intake phase defined in SKILL.md and processed by the eval_analyst_agent. * Boundary markers: The current instructions lack explicit structural delimiters to isolate external data from the agent's internal instruction set. * Capability inventory: The agent team is authorized to generate reports, draft announcements, and append data to the course_passport.yaml file; however, no shell execution or network capabilities are present in the scripts. * Sanitization: The references/eval_analysis_protocol.md file mandates the de-identification of student names and IDs and the filtering of abusive content prior to data entering the working set.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 04:05 PM
Security Audit — agent-trust-hub — teaching-reflector