grilling-designs
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its requirement to ingest and process data from external, potentially untrusted sources.
- Ingestion points: The agent is instructed to resolve answers from repository files, configuration, docs, tests, and commands (SKILL.md).
- Boundary markers: The instructions lack explicit delimiters or warnings to prevent the agent from following instructions embedded within the processed data.
- Capability inventory: The skill relies on the agent's ability to read the file system and execute shell commands (SKILL.md).
- Sanitization: There is no indication of filtering or sanitizing the data retrieved from files or commands.
- [COMMAND_EXECUTION]: The skill allows the agent to execute arbitrary shell commands to gather project context and resolve information gaps.
Audit Metadata