skills/mtgvim/tiger-kit/tk-grill/Gen Agent Trust Hub

tk-grill

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the analysis of external data, which introduces a surface for indirect prompt injection. Malicious instructions contained within processed files or repositories could influence the agent's behavior. \n
  • Ingestion points: The instructions specify resolving facts from "supplied files, repository, connected tools, or bounded public sources". \n
  • Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or ignore embedded instructions when reading external content. \n
  • Capability inventory: Impact is significantly mitigated as the skill explicitly forbids modifying the filesystem, Git state, or performing automated tool invocations. \n
  • Sanitization: No input validation or content filtering mechanisms are defined for the data sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 12:17 AM
Security Audit — agent-trust-hub — tk-grill