startup-grill

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill's instructions, scripts, or metadata.
  • [PROMPT_INJECTION]: The skill uses clear instructional boundaries (STOP gate) to prevent misuse for unintended tasks like brainstorming or building artifacts. It includes specific routing to appropriate skills and does not attempt to bypass agent safety filters.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file path access (e.g., .ssh, .aws), or network exfiltration was found. File operations are scoped to project-specific artifacts and local output directories.
  • [OBFUSCATION]: The skill content was analyzed for Base64, hex-encoding, homoglyphs, and zero-width characters. All content is transparent and readable.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted user data (markdown canvases, HTML pitch decks), its capabilities are restricted to file reads/writes and information synthesis. It lacks dangerous capabilities like subprocess execution or network operations that would elevate the risk of data ingestion.
  • [DYNAMIC_CONTEXT_INJECTION]: No use of shell-pre-execution syntax (!command) was detected in the skill definitions.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic code execution patterns (eval/exec) are present in the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 07:12 AM
Security Audit — agent-trust-hub — startup-grill