grilling
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input and environment data, creating an attack surface for indirect prompt injection.
- Ingestion points: Processes user-provided plans, decisions, and ideas. It also explicitly instructs the agent to explore the environment (filesystem and tools) to find facts (SKILL.md).
- Boundary markers: No specific delimiters or "ignore instructions" warnings are present for the interpolated data.
- Capability inventory: The skill allows the agent to use its full suite of tools and filesystem access to resolve dependencies.
- Sanitization: No explicit sanitization or filtering of environment data is mentioned.
Audit Metadata