ai-ml-expert
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection.
- Ingestion points: The agent ingests potentially untrusted data through the
WebSearchtool and theReadtool (specifically when accessing.claude/context/memory/learnings.md). - Boundary markers: No instructions are provided to the agent to use delimiters or 'ignore embedded instructions' warnings when handling content from external sources.
- Capability inventory: The skill utilizes the
Bash,Write, andEdittools, allowing for shell command execution and file system modifications. - Sanitization: The instructions do not specify any validation or sanitization procedures for data retrieved from external tools before it is processed or stored in memory.
Audit Metadata