tailrocks-grilling

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external and repository sources, which creates a potential surface for instructions embedded in that data to influence the agent's behavior.- Ingestion points: As noted in references/runtime-trust.md, the skill retrieves information from repository files, reports, fixtures, scripts, tool output, registry content, and web content.- Boundary markers: The skill includes robust defensive policies in references/runtime-trust.md, explicitly instructing the agent that embedded instructions in data cannot alter governing rules or authority.- Capability inventory: The skill is strictly limited to conversation and fact retrieval. SKILL.md and references/runtime-trust.md explicitly forbid writing to the repository, committing code, executing shell commands, or making external calls beyond fact-finding.- Sanitization: The instructions mandate treating all retrieved content as untrusted and cite the location of secrets rather than reading them, but they do not define specific programmatic sanitization or escaping steps for the retrieved text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:12 PM
Security Audit — agent-trust-hub — tailrocks-grilling