grilling
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied plans, decisions, or ideas and instructs the agent to autonomously fetch facts from the local environment (filesystem, tools) to support the analysis. This creates a surface where malicious user input could potentially influence the agent's tool usage or sub-agent behavior.
- Ingestion points: User input describing plans, decisions, or ideas in SKILL.md.
- Boundary markers: Absent; there are no instructions to sanitize or isolate the user's input from the tool-triggering logic.
- Capability inventory: Access to the filesystem and other environment tools via sub-agents as described in SKILL.md.
- Sanitization: Absent.
Audit Metadata