skills/noelrohi/skills/grilling/Gen Agent Trust Hub

grilling

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill builds a dynamic design tree based on user answers to formulate subsequent questions and actions. There are no instructions for sanitizing user input or using boundary markers to prevent the agent from interpreting malicious instructions embedded in the user's answers.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to 'dispatch a sub-agent' to the filesystem or tools whenever a 'fact' is needed from the environment. This autonomous lookup behavior bypasses user confirmation for specific data retrieval actions, which could be exploited to access sensitive files if the questioning path is manipulated.
  • [DATA_EXPOSURE]: By encouraging the agent to proactively 'look up' information in the environment rather than asking the user, the skill creates a risk of exposing local configuration files or private data during the 'fact-finding' phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 04:59 PM
Security Audit — agent-trust-hub — grilling