skills/vdelacou/atelier/grill-me/Gen Agent Trust Hub

grill-me

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior, obfuscation, or unauthorized data access patterns were detected. The skill's primary function is to guide the agent through a logical interrogation process with the user.
  • [PROMPT_INJECTION]: The skill instructions the agent to ingest data from the local codebase, which introduces a surface for indirect prompt injection if project files contain malicious instructions. 1. Ingestion points: Local codebase files and configuration settings (SKILL.md). 2. Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions found within the analyzed files. 3. Capability inventory: The agent performs file reads and can propose updates to .claude/LESSONS.md. 4. Sanitization: No explicit sanitization or verification of the content being read is requested.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 08:29 AM
Security Audit — agent-trust-hub — grill-me