grilling

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to operate with high autonomy when gathering information, which can be exploited by malicious user input.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data (plans/decisions) and has the capability to read the environment.
  • Ingestion points: The skill processes user-supplied plans, decisions, or ideas as the primary input for the 'grilling' process in SKILL.md.
  • Boundary markers: Absent. There are no instructions to treat user-provided plans as data only or to ignore embedded instructions.
  • Capability inventory: The agent is explicitly told to 'dispatch a sub-agent' to query the filesystem and environment tools (SKILL.md).
  • Sanitization: Absent. There is no logic to filter which 'facts' or file paths the agent is allowed to access.
  • [COMMAND_EXECUTION]: The skill encourages autonomous tool and filesystem usage ('Finding facts is your job, never the user's') without requiring user confirmation for each lookup, which could lead to unintended data exposure if the agent misinterprets its instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 12:57 PM
Security Audit — agent-trust-hub — grilling