workflow-grilling

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing untrusted user input while maintaining high-privilege capabilities such as shell command execution.
  • Ingestion points: The agent ingests a "plan, decision, or idea" directly from the user which serves as the context for the entire grilling session (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions to ignore instructions embedded within the user's plan.
  • Capability inventory: The skill explicitly authorizes the agent to explore the filesystem, git history, documentation, and run shell commands to verify facts (Rule 3 in SKILL.md).
  • Sanitization: No sanitization or validation of the user's plan is performed before the agent potentially uses that context to determine which commands to run for "fact-finding".
  • [SAFE]: The skill includes a strong behavioral constraint ("Do not act until confirmed") that explicitly forbids the agent from editing files, scaffolding, or starting build work until the user confirms a shared understanding, which mitigates the risk of the agent autonomously executing a malicious plan.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:42 PM
Security Audit — agent-trust-hub — workflow-grilling