grill-with-docs

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and align with existing documentation in the codebase, which presents a surface for indirect prompt injection if those files contain malicious instructions.\n
  • Ingestion points: The skill reads CONTEXT.md, CONTEXT-MAP.md, and ADR files (e.g., in docs/adr/) to enforce domain terminology and cross-reference decisions with code.\n
  • Boundary markers: The instructions lack explicit delimiters or warnings to the agent to ignore any natural language instructions that might be embedded within the project's documentation files.\n
  • Capability inventory: The skill allows the agent to update files (CONTEXT.md, ADRs) and communicate through a specific Slack channel (#brain-joel).\n
  • Sanitization: There is no requirement or logic provided to sanitize or validate the content retrieved from the codebase before it is used to influence the agent's conversational logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — grill-with-docs