grillkit
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is designed to ingest and analyze untrusted data from the local environment.
- Ingestion points: Processes external data from plan files, pull requests, and codebase content using tools like Read, Grep, and Glob as described in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or technical constraints to prevent the agent from potentially executing instructions embedded within the analyzed text, although the procedural requirement to reflect understanding back to the user serves as a manual validation step.
- Capability inventory: The skill is configured with Bash, Write, Edit, Task, Agent, and Skill tools, which provides a significant capability set if an indirect injection were successful.
- Sanitization: There is no evidence of automated sanitization or instruction-filtering for content read from the filesystem before it is processed by the agent.
Audit Metadata