bb-clarify
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a logical workflow for clarifying technical requirements and updating a local feature specification file. It does not perform any network operations or access sensitive credentials.
- [DATA_EXFILTRATION]: The skill interacts with local project files (specifically
FEATURE_SPEC). It reads the file to identify ambiguities and writes clarifications back to it. No external transmission of data was detected. - [COMMAND_EXECUTION]: The instructions include guidance on escaping single quotes within arguments, which is a standard safety measure for handling user input. No arbitrary command execution patterns are present.
- [PROMPT_INJECTION]: The skill processes content from the
FEATURE_SPECfile, which represents an indirect prompt injection surface. This is handled through a structured analysis process and localized file updates. - Ingestion points: Reads content from
FEATURE_SPECfor ambiguity scanning. - Boundary markers: The skill uses a structured taxonomy to segment the analysis, though explicit ignore markers for embedded instructions are not defined.
- Capability inventory: The skill has capabilities to read and write to the feature directory and spec file.
- Sanitization: Implements argument escaping to prevent command injection when processing user input.
Audit Metadata