klimkit-grill-me
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its workflow of ingesting untrusted data from the repository and the internet.\n
- Ingestion points: The skill reads the codebase, documentation, and existing task notes, and performs web searches for external context (SKILL.md, Step 5).\n
- Boundary markers: The instructions lack delimiters or explicit directives to ensure the agent ignores or isolates instructions that might be embedded in the files or web content being processed.\n
- Capability inventory: The agent has the ability to read and write files within the project (specifically in the .klimkit/ directory) and perform web research.\n
- Sanitization: The instructions do not specify any validation, sanitization, or escaping of the content ingested from the codebase or the web before it is used to generate questions or written to notes.
Audit Metadata