ai-ml-expert

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection.
  • Ingestion points: The agent ingests potentially untrusted data through the WebSearch tool and the Read tool (specifically when accessing .claude/context/memory/learnings.md).
  • Boundary markers: No instructions are provided to the agent to use delimiters or 'ignore embedded instructions' warnings when handling content from external sources.
  • Capability inventory: The skill utilizes the Bash, Write, and Edit tools, allowing for shell command execution and file system modifications.
  • Sanitization: The instructions do not specify any validation or sanitization procedures for data retrieved from external tools before it is processed or stored in memory.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 02:04 PM