tk-grill
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the analysis of external data, which introduces a surface for indirect prompt injection. Malicious instructions contained within processed files or repositories could influence the agent's behavior. \n
- Ingestion points: The instructions specify resolving facts from "supplied files, repository, connected tools, or bounded public sources". \n
- Boundary markers: The skill lacks explicit instructions for the agent to use delimiters or ignore embedded instructions when reading external content. \n
- Capability inventory: Impact is significantly mitigated as the skill explicitly forbids modifying the filesystem, Git state, or performing automated tool invocations. \n
- Sanitization: No input validation or content filtering mechanisms are defined for the data sources.
Audit Metadata