grilling

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local repository environment to build its decision tree and context.\n
  • Ingestion points: Reads project-specific data from .agents/projects/<project>/CONTEXT.md and LINKS.md, and inspects the broader repository for facts.\n
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions found within these ingested files.\n
  • Capability inventory: The skill has the ability to read from the repository and write/record project facts, choices, and technical decisions (ADRs) back to the project artifacts.\n
  • Sanitization: No explicit sanitization or validation of the ingested content is described before it is used to formulate questions or record decisions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 06:37 AM
Security Audit — agent-trust-hub — grilling