grilling
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to automatically gather information from the local environment (filesystem and tools) using sub-agents to resolve questions in a design tree.
- Ingestion points: Data is pulled from the local filesystem and external tool outputs as specified in the instructions (SKILL.md).
- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the gathered environment data, which could allow malicious content in files to influence the agent.
- Capability inventory: The agent is encouraged to use filesystem and tool access capabilities autonomously (SKILL.md).
- Sanitization: No sanitization or verification steps are defined for the information retrieved from the environment before it is processed into the user's decision tree.
Audit Metadata