grilling
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided content (plans, decisions, or ideas) to build a design tree and instructions the agent to use tools to verify facts related to that input.
- Ingestion points: User-supplied descriptions of plans or ideas processed in SKILL.md.
- Boundary markers: The instructions do not define explicit delimiters or warnings to ignore instructions embedded within the user's plan.
- Capability inventory: The skill authorizes the use of sub-agents to access the 'filesystem' and other 'tools' to retrieve environment facts (SKILL.md).
- Sanitization: No specific sanitization or filtering logic is described for the content being processed.
Audit Metadata