grill-me
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or unauthorized data access patterns were detected. The skill's primary function is to guide the agent through a logical interrogation process with the user.
- [PROMPT_INJECTION]: The skill instructions the agent to ingest data from the local codebase, which introduces a surface for indirect prompt injection if project files contain malicious instructions. 1. Ingestion points: Local codebase files and configuration settings (SKILL.md). 2. Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions found within the analyzed files. 3. Capability inventory: The agent performs file reads and can propose updates to .claude/LESSONS.md. 4. Sanitization: No explicit sanitization or verification of the content being read is requested.
Audit Metadata