batch-grill-me
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process user answers to build a 'design tree' and autonomously dispatch sub-agents to access the environment (filesystem, tools) for fact-finding.
- Ingestion points: User-provided answers to 'frontier' questions in each round of the interview (SKILL.md).
- Boundary markers: The prompt lacks explicit delimiters or instructions for the agent to separate user input from its own execution instructions, increasing the risk of the agent obeying commands embedded in user responses.
- Capability inventory: The skill explicitly grants authority for autonomous environment exploration and tool usage via sub-agents (SKILL.md).
- Sanitization: No mechanisms for validating, filtering, or escaping user input are defined before the data influences the sub-agent's investigative actions.
Audit Metadata