skills/brave/brave-search-skills/bx/Gen Agent Trust Hub

bx

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install the 'bx' utility using a shell script fetched from the official Brave Search CLI GitHub repository. This is presented as the standard setup procedure for the vendor's tool.
  • [COMMAND_EXECUTION]: The skill describes how to execute the 'bx' binary for various search and research tasks. These commands interact with the Brave Search API and are intended for RAG and grounding workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted data from the public web.
  • Ingestion points: Web search results, snippets, and synthesized answers returned by the 'bx' command in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters to isolate external search results from the agent's core instructions.
  • Capability inventory: The agent is granted the ability to perform network-based web searches and process the resulting data.
  • Sanitization: The skill relies on the agent's internal filtering and the pre-extracted nature of the tool's output to mitigate malicious content in search results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:25 PM
Security Audit — agent-trust-hub — bx