grilling
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user input (plans, decisions, or ideas). It explicitly instructs the agent to proactively "dispatch a sub-agent" to gather facts from the environment (filesystem, tools, etc.) before the questioning begins. There are no defined boundary markers or sanitization requirements to prevent instructions embedded within the user's plan from manipulating the behavior of these sub-agents.
- [COMMAND_EXECUTION]: The instruction to "dispatch a sub-agent to find [facts from environment]" encourages automated tool usage and filesystem access based on inferred needs from user-provided content. This capability increases the potential impact if the agent is tricked into accessing sensitive files or executing commands as part of its fact-finding mission.
Audit Metadata