grilling

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided plans, ideas, and decisions which constitute untrusted data. It explicitly directs the agent to perform environment exploration (accessing the filesystem and tools) to gather facts based on this input, creating a vector where malicious instructions inside a user's plan could influence the agent's behavior in the local environment.\n
  • Ingestion points: User-provided plans, decisions, ideas, and answers to frontier questions as described in SKILL.md.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat user-provided data as potentially untrusted or to ignore embedded instructions within that data.\n
  • Capability inventory: The skill authorizes the agent to access the filesystem and use tools through sub-agents to verify facts (SKILL.md).\n
  • Sanitization: No validation or sanitization steps are defined to filter user input before it is used to determine which environment facts the agent should investigate.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:48 AM
Security Audit — agent-trust-hub — grilling