grilling
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied plans and designs and directs the agent to explore the project codebase, creating a surface for indirect prompt injection via external content.
- Ingestion points: User-provided plan descriptions and codebase files (SKILL.md).
- Boundary markers: No delimiters or instructions to ignore instructions within the ingested content are present.
- Capability inventory: The skill utilizes codebase exploration tools (file system reads).
- Sanitization: No input validation or sanitization is specified.
- [SAFE]: The skill includes references to a repository on a well-known service (GitHub) for attribution and source documentation (SKILL.md).
Audit Metadata