grilling
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill directs the agent to ingest and analyze user-provided plans and codebase files, potentially allowing malicious instructions in those files to influence behavior.
- Ingestion points: User design descriptions and project codebase files.
- Boundary markers: Absent; there are no instructions to the agent to treat external content strictly as data or ignore embedded instructions.
- Capability inventory: File read access through the codebase exploration feature.
- Sanitization: None; ingested content is not validated or sanitized before processing.
- [NO_CODE]: The skill consists solely of markdown instructions and does not include any scripts, libraries, or executable code.
Audit Metadata