bidwriter

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the agent's standard document-processing environment, focusing on generating structured Markdown content from user-provided bid requirements.
  • [EXTERNAL_DOWNLOADS]: While the instructions suggest using external OCR tools like MinerU or WPS OCR for processing scanned PDFs, the skill does not automate the download or installation of these tools, nor does it contain any remote code execution patterns.
  • [DATA_EXFILTRATION]: No network operations, hardcoded credentials, or unauthorized file access patterns were identified. The skill correctly identifies and categorizes sensitive bid information while keeping it within the project's local directory structure.
  • [PROMPT_INJECTION]: The skill contains clear behavioral constraints, such as prohibiting the fabrication of qualifications and ensuring technical responses are data-driven. It includes a specific rule delegating pricing decisions to human users to prevent AI-generated commercial errors.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external tender documents which could potentially contain adversarial instructions. However, the risk is mitigated by the skill's core mandate for a 20% human review phase and its lack of high-privilege tool access (e.g., no shell execution or direct internet access).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 09:34 AM
Security Audit — agent-trust-hub — bidwriter