grill-me
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security threats were identified. The skill implements a natural language workflow for interviewing users about their plans. It does not perform network requests, execute arbitrary shell commands, or include obfuscated content.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided plans or design documents (Step 0). While this represents a data ingestion surface, the skill's capabilities are limited to natural language interaction and read-only codebase exploration. There are no explicit boundary markers or sanitization steps defined, but the risk is negligible given the conversational nature of the tool.
- [METADATA_POISONING]: The metadata in README.md and the SKILL.md frontmatter correctly describe the skill's purpose and author. No deceptive instructions or hidden payloads were found in the metadata fields.
Audit Metadata