skills/evans-sam/skills/grill-me/Gen Agent Trust Hub

grill-me

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to 'explore the codebase' to resolve questions about a design or plan. This creates an attack surface where untrusted data within code files or the user's design plan could contain hidden instructions intended to divert the agent from its primary task.
  • Ingestion points: User-provided plans and project codebase files.
  • Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in SKILL.md.
  • Capability inventory: The skill utilizes the agent's file-reading and analysis capabilities to inspect the local environment.
  • Sanitization: No sanitization or filtering logic is specified for the content retrieved from the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:21 AM
Security Audit — agent-trust-hub — grill-me