w-grill

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads local project documentation, including README, DESIGN.md, and ADRs, to gather facts. While these files represent an external data ingestion surface that could theoretically contain malicious instructions, the skill's design limits the impact by only using the information to formulate questions for the user. Furthermore, it explicitly requires user confirmation before any implementation or action is taken.
  • [SAFE]: The skill's logic is transparent and focuses on structured user interaction. No patterns of obfuscation, remote code execution, or unauthorized data access were identified. It adheres to safety principles by instructing the agent to wait for user confirmation before acting on the gathered information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:21 PM
Security Audit — agent-trust-hub — w-grill