grilling
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The instructions describe a purely conversational persona meant for design review. There is no evidence of command injection, data exfiltration, or obfuscated content.\n- [PROMPT_INJECTION]: The skill processes untrusted user plans, creating a surface for indirect prompt injection.\n
- Ingestion points: User-supplied plan descriptions in SKILL.md.\n
- Boundary markers: Absent; no specific delimiters are defined to wrap user input.\n
- Capability inventory: The skill references exploring the codebase for facts, which utilizes the agent's built-in file-reading tools.\n
- Sanitization: None; the skill relies on the underlying model's safety guardrails.
Audit Metadata