grilling
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions and metadata are focused on a legitimate logic-based interviewing task and do not contain any malicious code, obfuscation, or persistence mechanisms.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided answers to influence the next round of questioning, which represents a standard surface for indirect injection that is common in conversational agents.
- Ingestion points: User responses to the round-based frontier questions are processed to update the design tree (SKILL.md).
- Boundary markers: The skill uses a structured question-and-answer format (❓ Q# and ➡️) but lacks explicit boundary instructions to isolate user content.
- Capability inventory: The instructions permit the agent to dispatch sub-agents to query the filesystem and other tools for fact-finding (SKILL.md).
- Sanitization: No specific input sanitization or validation routines are defined for the user answers.
Audit Metadata