ptlam-grilling

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests repository files and documentation to construct decision maps, creating a potential surface for indirect prompt injection. 1. Ingestion points: Reads repository files, product documents, and code from the workspace (specified in SKILL.md and ptlam-modeling-domain/SKILL.md). 2. Boundary markers: The skill uses a structured session schema but does not specify explicit delimiters for external content. 3. Capability inventory: The agent can write to specific files like CONTEXT.md and session records (specified in references/grilling-session-schema.md and skills/ptlam-modeling-domain/SKILL.md). 4. Sanitization: The skill provides explicit instructions to exclude secrets and personal data from records, mitigating exposure risk.
  • [EXTERNAL_DOWNLOADS]: The skill identifies a reference to a GitHub repository in ACKNOWLEDGEMENTS.md for attribution. This is a static reference to a well-known service and does not involve automated downloads or code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 09:47 AM
Security Audit — agent-trust-hub — ptlam-grilling