grill-with-docs

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process data from the project's codebase and documentation files without explicit safety boundaries.
  • Ingestion points: The agent is instructed to read CONTEXT.md, CONTEXT-MAP.md, files in docs/adr/, and the project's source code (src/) to identify terminology conflicts and verify logic.
  • Boundary markers: There are no instructions providing delimiters or warnings for the agent to ignore potentially malicious instructions embedded in the project files it reads.
  • Capability inventory: Across its instructions, the skill requires the agent to read existing files and perform write operations to update documentation or create new ADR files based on its analysis of external content.
  • Sanitization: The skill lacks mechanisms for sanitizing or validating the content retrieved from the file system before it is incorporated into the agent's context or written back to the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — grill-with-docs