grilling
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.
- Ingestion points: Untrusted data enters the agent context via user-provided plans or designs mentioned in the instructions (SKILL.md).
- Boundary markers: Absent; there are no delimiters or explicit instructions to ignore commands embedded within the user's plan.
- Capability inventory: The skill instructs the agent to explore the codebase, which involves file read access (SKILL.md).
- Sanitization: Absent; the instructions do not specify any validation, escaping, or filtering of the user-provided content.
Audit Metadata