grill-me
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to 'explore the codebase' to resolve questions about a design or plan. This creates an attack surface where untrusted data within code files or the user's design plan could contain hidden instructions intended to divert the agent from its primary task.
- Ingestion points: User-provided plans and project codebase files.
- Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in SKILL.md.
- Capability inventory: The skill utilizes the agent's file-reading and analysis capabilities to inspect the local environment.
- Sanitization: No sanitization or filtering logic is specified for the content retrieved from the codebase.
Audit Metadata