grill-me
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions are focused on architectural review (grilling) and the maintenance of local documentation files like CONTEXT.md and ADRs. It does not perform any dangerous operations.
- [SAFE]: No external network requests, remote code execution, or credential exposure patterns were identified in the skill files.
- [SAFE]: No obfuscation techniques or malicious prompt injection patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill reads from and writes to repository files, creating a potential surface for indirect prompt injection if the processed repository contains malicious content.
- Ingestion points: Reads from project files including
CONTEXT.md,CONTEXT-MAP.md,docs/adr/, and source code undersrc/. - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the documentation files it processes.
- Capability inventory: The agent is authorized to read local repository files and create or update documentation files (ADRs and glossaries).
- Sanitization: No explicit content sanitization or validation logic is specified for the data being read from the project files.
Audit Metadata