batch-grill-me

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of instructional markdown and configuration files. No scripts (e.g., Python, JavaScript) or binary executables are included.
  • [PROMPT_INJECTION]: The instructions direct the agent to autonomously fetch facts from the environment (filesystem, tools, etc.) using sub-agents. 1. Ingestion points: Environment facts gathered from the filesystem and tool outputs, as well as user responses. 2. Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from following commands embedded within the gathered environment data. 3. Capability inventory: The skill leverages filesystem access and tool execution via the agent's native capabilities or sub-agents. 4. Sanitization: No explicit sanitization or validation of the retrieved facts is specified. This creates a surface for indirect prompt injection where malicious content in the filesystem could influence the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 07:24 AM
Security Audit — agent-trust-hub — batch-grill-me