grill-me

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local project data (source code and existing documentation) to inform its responses and update project files. This creates a surface for indirect prompt injection where malicious instructions embedded in the analyzed code or documentation could influence the agent's behavior during the grilling session.
  • Ingestion points: Reads project files including CONTEXT.md, CONTEXT-MAP.md, docs/adr/, and the src/ directory as described in SKILL.md.
  • Boundary markers: No explicit markers or instructions to ignore embedded commands are present when reading external project files.
  • Capability inventory: The skill is authorized to read project files and write or create Markdown documentation files (CONTEXT.md, ADRs). No network access or shell command execution capabilities are utilized.
  • Sanitization: No sanitization or validation of ingested content is mentioned before it is processed or written back to the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:03 AM
Security Audit — agent-trust-hub — grill-me