exercise-builder
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [SAFE] (SAFE): No malicious instructions, obfuscation, or data exfiltration patterns were detected. The skill is functionally restricted to text manipulation within a tutorial context.
- [PROMPT_INJECTION] (SAFE): No override markers or jailbreak attempts are present; instructions remain within the boundaries of a content generation tool.
- [DATA_EXPOSURE] (INFO): The skill interacts with
outline/module_plan.yml. This file contains tutorial metadata and does not expose system secrets, user credentials, or sensitive environmental data. - [COMMAND_EXECUTION] (SAFE): No shell commands or system-level scripts are invoked.
- [INDIRECT_PROMPT_INJECTION] (LOW): While the skill ingests data from an external YAML file, its capabilities are limited to writing back to that same structured file. It does not provide an execution or exfiltration pathway for malicious instructions embedded in the input data.
Audit Metadata