grill-with-docs

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a documentation-oriented tool meant for reviewing architectural plans, domain language, and decisions within a project repository. It does not perform any high-risk operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is instructed to read and process external project files (ADRs, context files, READMEs) which could contain malicious instructions. However, the risk is negligible because the skill does not use tools capable of executing code, making network requests, or writing to the filesystem.
  • Ingestion points: SKILL.md identifies several local files for ingestion: .opencode-context.md, .opencode-jce/context/, CONTEXT.md, docs/adr/, and README.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands within the ingested text.
  • Capability inventory: The skill lacks any capabilities for subprocess execution, remote network operations, or sensitive file access.
  • Sanitization: No sanitization or validation of the ingested content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — grill-with-docs