grilling
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local repository environment to build its decision tree and context.\n
- Ingestion points: Reads project-specific data from
.agents/projects/<project>/CONTEXT.mdandLINKS.md, and inspects the broader repository for facts.\n - Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions found within these ingested files.\n
- Capability inventory: The skill has the ability to read from the repository and write/record project facts, choices, and technical decisions (ADRs) back to the project artifacts.\n
- Sanitization: No explicit sanitization or validation of the ingested content is described before it is used to formulate questions or record decisions.
Audit Metadata