skills/shipshitdev/skills/grilling/Gen Agent Trust Hub

grilling

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and does not contain code, network operations, or privileged system access. It follows standard design patterns for agentic dialogue.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from users and external repository documentation to generate frontier questions. This represents a standard attack surface for indirect prompt injection, though risk is minimized by the skill's restricted capabilities.
  • Ingestion points: User-provided plans, decisions, and optional repository or documentation context (SKILL.md).
  • Boundary markers: None explicitly defined in the instructions to separate untrusted context from instructions.
  • Capability inventory: Read-only fact-finding and exploration sub-agents for settling facts (SKILL.md).
  • Sanitization: No explicit sanitization or filtering of external content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:08 PM
Security Audit — agent-trust-hub — grilling