search
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content from search engines (Google, Bing, Yandex) and discovery tools, which creates a surface for indirect prompt injection attacks where malicious instructions hidden in search results could attempt to influence agent behavior.\n
- Ingestion points: Web search results fetched via
bdata searchandbdata discover(described inSKILL.mdandreferences/patterns.md).\n - Boundary markers: Absent. The instructions do not define clear delimiters or warnings for the agent to disregard instructions within the scraped content.\n
- Capability inventory: The skill utilizes the
bdataCLI for network access, performs file system writes, and uses shell processing utilities.\n - Sanitization: The skill employs
jqto extract structured data fields andgrepto filter out block-page content, providing a degree of technical sanitization.\n- [COMMAND_EXECUTION]: The skill provides complex shell command patterns for batch processing and result filtering.\n - Evidence:
references/patterns.mdcontains shell loops and pipes usingxargs,bash -c, andmd5sumto automate search tasks.\n- [DYNAMIC_EXECUTION]: The skill documents patterns for dynamically constructing shell commands based on variable inputs.\n - Evidence: Shell scripts in
references/patterns.mduse string interpolation to build command arguments and file paths. The documentation demonstrates proper quoting (e.g., "$q", "$url") to mitigate injection risks.
Audit Metadata