grill-with-docs
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and align with existing documentation in the codebase, which presents a surface for indirect prompt injection if those files contain malicious instructions.\n
- Ingestion points: The skill reads
CONTEXT.md,CONTEXT-MAP.md, and ADR files (e.g., indocs/adr/) to enforce domain terminology and cross-reference decisions with code.\n - Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore any natural language instructions that might be embedded within the project's documentation files.\n
- Capability inventory: The skill allows the agent to update files (
CONTEXT.md, ADRs) and communicate through a specific Slack channel (#brain-joel).\n - Sanitization: There is no requirement or logic provided to sanitize or validate the content retrieved from the codebase before it is used to influence the agent's conversational logic.
Audit Metadata