ptlam-grilling
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it is instructed to analyze and incorporate data from arbitrary files within a user's repository.
- Ingestion points: In
SKILL.md, the agent is directed to "Inspect repository files, tools, prior decisions" and "read the complete file" of existing sessions to establish context. - Boundary markers: The skill lacks defined delimiters or explicit instructions for the agent to disregard instructions embedded within the ingested data.
- Capability inventory: The skill instructions involve file system read and write operations across the project workspace.
- Sanitization: There are no instructions for sanitizing or validating content retrieved from external files before it is processed by the agent.
Audit Metadata