interview
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a command-line tool named 'bd' to retrieve project context ('bd show') and update epics or issues ('bd update'). This is part of the skill's intended functionality for recording decisions and tracking progress.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external and potentially untrusted sources, which could contain malicious instructions.\n
- Ingestion points: User input from the 'caller' and project data retrieved from trackers, documentation, and source code.\n
- Boundary markers: The instructions lack explicit delimiters or specific directives for the agent to treat ingested content as untrusted data.\n
- Capability inventory: The skill can execute shell commands via 'bd' and modify external intent sources (epics/issues).\n
- Sanitization: No explicit sanitization or validation of the ingested content is described before it is recorded or used in recommendations.
Audit Metadata