workflow-grilling
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data in the form of plans, ideas, and decision-making details. This creates a potential surface for indirect prompt injection. However, the skill includes strong process guardrails such as requiring the agent to ask only one question at a time and prohibiting any automated actions (edits, scaffolding) until a shared understanding is confirmed by the user.
- [EXTERNAL_DOWNLOADS]: The skill mentions a GitHub repository for methodology attribution. This is a reference to a well-known source and does not involve the automated fetching or execution of remote scripts.
Audit Metadata