grilling
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to retrieve facts from the repository and environment using tools like Bash and Read, which are then used to formulate questions. This represents a vulnerability surface where malicious instructions in environmental files could influence agent behavior.
- Ingestion points: Data entering the agent context via Read, Grep, Glob, and Bash as specified in the instructions and example sections.
- Boundary markers: Instructions do not provide delimiters or 'ignore embedded instructions' warnings for data retrieved from the environment.
- Capability inventory: The agent has access to Bash, Read, Grep, Glob, and Task tools.
- Sanitization: There is no mention of escaping, filtering, or validation of content from environmental sources before processing.
Audit Metadata