grill-me
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes local project data (source code and existing documentation) to inform its responses and update project files. This creates a surface for indirect prompt injection where malicious instructions embedded in the analyzed code or documentation could influence the agent's behavior during the grilling session.
- Ingestion points: Reads project files including CONTEXT.md, CONTEXT-MAP.md, docs/adr/, and the src/ directory as described in SKILL.md.
- Boundary markers: No explicit markers or instructions to ignore embedded commands are present when reading external project files.
- Capability inventory: The skill is authorized to read project files and write or create Markdown documentation files (CONTEXT.md, ADRs). No network access or shell command execution capabilities are utilized.
- Sanitization: No sanitization or validation of ingested content is mentioned before it is processed or written back to the filesystem.
Audit Metadata