grilling
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by directing the agent to autonomously fetch facts from the environment to inform its questioning process. 1. Ingestion points: Data is ingested from the local filesystem and external tools in SKILL.md. 2. Boundary markers: Absent; there are no instructions to use delimiters or ignore potentially malicious instructions within retrieved content. 3. Capability inventory: Sub-agents are used to perform filesystem access and tool execution in SKILL.md. 4. Sanitization: Absent; no validation or filtering of external content is specified.
- [COMMAND_EXECUTION]: The skill instructions allow the agent to autonomously execute environment tools via sub-agents to retrieve information as described in the fact-finding section of SKILL.md.
Audit Metadata