grilling
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to autonomously search the environment for information to answer questions, creating an attack surface.
- Ingestion points: Filesystem and environmental tools used to retrieve "facts" (SKILL.md).
- Boundary markers: The instructions lack delimiters or safety warnings for handling external content retrieved from the environment.
- Capability inventory: Filesystem access and sub-agent orchestration (SKILL.md).
- Sanitization: No sanitization or verification of data retrieved from the environment is specified.
- [COMMAND_EXECUTION]: The skill explicitly encourages the agent to use sub-agents and environment tools to perform automated exploration and fact-finding (SKILL.md).
Audit Metadata