grub-search
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it is designed to process and search through untrusted data from various external sources.
- Ingestion points: The
grub()function accepts local filesystem paths, globs, and remote URLs (e.g.,grub('./docs'),grub('https://example.com/guide')) to build search indices. - Boundary markers: The instructions lack specific delimiters or guardrails to ensure the agent ignores any instructions found within the data being indexed.
- Capability inventory: The skill possesses the ability to read local files and perform network requests to retrieve website content.
- Sanitization: There is no evidence of sanitization or content filtering performed on the data retrieved from the ingestion points.
- [EXTERNAL_DOWNLOADS]: The skill relies on the
grubPython library and mentions an optionalsemanticextension that downloads machine learning models fromsentence-transformers. These are documented as vendor-provided resources associated with the author 'thorwhalen'.
Audit Metadata