grilling

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for a conversational interview process. It does not contain obfuscation, remote code execution, or credential exfiltration patterns.
  • [PROMPT_INJECTION]: The skill processes untrusted user input (plans or ideas) and interacts with the filesystem, creating a surface for indirect prompt injection. • Ingestion points: Processes user-provided plans and ideas in SKILL.md. • Boundary markers: None present to distinguish instructions from user-provided data. • Capability inventory: Accesses the filesystem and other tools as mentioned in SKILL.md. • Sanitization: No sanitization or validation logic is implemented.
  • [DATA_EXFILTRATION]: The skill instructions allow the agent to explore the local filesystem to find facts related to the user's plan. While this is intended for gathering context, users should be aware that the agent is permitted to read local files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 02:24 AM
Security Audit — agent-trust-hub — grilling