grilling

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to gather facts from the environment (filesystem, tools, etc.) using sub-agents. This creates a surface where untrusted data from the local environment could be ingested into the prompt context. However, the skill provides a clear structure for its output (design tree and rounds) and uses these facts solely for question generation, which follows standard operational guidelines for such agents.
  • [COMMAND_EXECUTION]: The instructions authorize the use of tools and sub-agents to explore the filesystem for fact-finding. This is an intended capability of the skill to avoid asking the user for information that can be retrieved programmatically. There are no patterns suggesting the execution of arbitrary or dangerous shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 09:17 AM
Security Audit — agent-trust-hub — grilling