grilling
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to autonomously gather facts from the environment to inform the questioning process, which creates a potential vulnerability to data-driven instructions.
- Ingestion points: Environment facts derived from the file system and external tools (SKILL.md).
- Boundary markers: The instructions lack specific boundary markers or delimiters to separate ingested facts from the agent's internal reasoning or output logic.
- Capability inventory: The skill utilizes tool-calling capabilities and sub-agents to investigate the file system and environment (SKILL.md).
- Sanitization: There is no mention of sanitizing or validating external data before it is processed into the 'design tree' used to generate user questions.
Audit Metadata