gremlin
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to load and trust content from multiple external local file paths to guide its behavior. Ingestion points: Absolute local file paths defined in SKILL.md (e.g., /Users/joel/Code/badass-courses/gremlin/skills/gremlin/SKILL.md). Boundary markers: None; the instructions explicitly tell the agent to load these files for 'truth' without providing delimiters or warnings to ignore potentially malicious embedded instructions. Capability inventory: The skill instructs the agent to load other repo-local skills which may contain their own capabilities. Sanitization: No mechanism is present to validate or filter the content of the referenced files before the agent processes them.
Audit Metadata