skills/thorwhalen/grub/grub-search/Gen Agent Trust Hub

grub-search

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it is designed to process and search through untrusted data from various external sources.
  • Ingestion points: The grub() function accepts local filesystem paths, globs, and remote URLs (e.g., grub('./docs'), grub('https://example.com/guide')) to build search indices.
  • Boundary markers: The instructions lack specific delimiters or guardrails to ensure the agent ignores any instructions found within the data being indexed.
  • Capability inventory: The skill possesses the ability to read local files and perform network requests to retrieve website content.
  • Sanitization: There is no evidence of sanitization or content filtering performed on the data retrieved from the ingestion points.
  • [EXTERNAL_DOWNLOADS]: The skill relies on the grub Python library and mentions an optional semantic extension that downloads machine learning models from sentence-transformers. These are documented as vendor-provided resources associated with the author 'thorwhalen'.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 02:27 AM
Security Audit — agent-trust-hub — grub-search