skills/alannkl/skills/grill-to-plan/Gen Agent Trust Hub

grill-to-plan

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources and possesses file-writing capabilities, creating a surface for indirect prompt injection.\n
  • Ingestion points: Workflow step 3 in SKILL.md instructs the agent to inspect the codebase, documentation, issue tracker, and session logs, which may contain untrusted content.\n
  • Boundary markers: Absent. There are no specific instructions or delimiters defined to prevent the agent from following instructions embedded within the files it inspects.\n
  • Capability inventory: The skill is authorized to write and update multiple files including CONTEXT.md, plan.md, session.md, and Architectural Decision Records (ADRs) as detailed in SKILL.md steps 7, 8, and 9 and in the reference formats.\n
  • Sanitization: Absent. No explicit sanitization or validation of the content extracted from the codebase or issue tracker is performed before being used to generate project documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:07 AM
Security Audit — agent-trust-hub — grill-to-plan