grilling
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to retrieve facts from the filesystem and environmental tools to support the grilling process. This creates a vector where instructions embedded in external files could subvert the agent's logic.\n
- Ingestion points: Data retrieved from the local filesystem or environment tools to verify facts during the design process (SKILL.md).\n
- Boundary markers: None. The instructions do not prescribe the use of delimiters or specific prompts to ensure that retrieved data is treated as untrusted content (SKILL.md).\n
- Capability inventory: Sub-agent execution for filesystem access and tool calls to
domain-modelingandshape-design(SKILL.md).\n - Sanitization: No sanitization, validation, or filtering of environmental data is specified before it is integrated into the agent's context.
Audit Metadata