grill-me
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown-based instructions for the agent and does not include any executable scripts, compiled binaries, or external configuration files.\n- [PROMPT_INJECTION]: The skill instructions direct the agent to 'explore the codebase' to answer questions, which establishes an indirect prompt injection surface where untrusted data from the codebase could influence the agent's behavior.\n
- Ingestion points: Local codebase files as per directives in SKILL.md.\n
- Boundary markers: Absent; there are no instructions provided to the agent to treat codebase content as untrusted or to ignore embedded commands.\n
- Capability inventory: The skill leverages the agent's ability to read and explore the local filesystem to inform its interview responses.\n
- Sanitization: Absent; the skill does not define any filtering or validation for the content retrieved from the codebase.
Audit Metadata