grilling

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill directs the agent to ingest and analyze user-provided plans and codebase files, potentially allowing malicious instructions in those files to influence behavior.
  • Ingestion points: User design descriptions and project codebase files.
  • Boundary markers: Absent; there are no instructions to the agent to treat external content strictly as data or ignore embedded instructions.
  • Capability inventory: File read access through the codebase exploration feature.
  • Sanitization: None; ingested content is not validated or sanitized before processing.
  • [NO_CODE]: The skill consists solely of markdown instructions and does not include any scripts, libraries, or executable code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 11:17 AM
Security Audit — agent-trust-hub — grilling