ziw-grill
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted data from repository files.
- Ingestion points: Reads PRDs, ADRs, ideas, and source code from the repository environment.
- Boundary markers: The instructions do not specify the use of delimiters or boundary markers when interpolating ingested content into the agent's internal reasoning loop.
- Capability inventory: The skill has permissions to read local files and write updated markdown specifications to the
docs/directory. - Sanitization: No explicit sanitization or filtering of external content is mentioned.
- Mitigation: The skill implements a strict requirement for explicit user confirmation before any artifacts are modified or status changes occur, providing a significant human-in-the-loop defense against automated injection attacks.
Audit Metadata