bb-clarify

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a logical workflow for clarifying technical requirements and updating a local feature specification file. It does not perform any network operations or access sensitive credentials.
  • [DATA_EXFILTRATION]: The skill interacts with local project files (specifically FEATURE_SPEC). It reads the file to identify ambiguities and writes clarifications back to it. No external transmission of data was detected.
  • [COMMAND_EXECUTION]: The instructions include guidance on escaping single quotes within arguments, which is a standard safety measure for handling user input. No arbitrary command execution patterns are present.
  • [PROMPT_INJECTION]: The skill processes content from the FEATURE_SPEC file, which represents an indirect prompt injection surface. This is handled through a structured analysis process and localized file updates.
  • Ingestion points: Reads content from FEATURE_SPEC for ambiguity scanning.
  • Boundary markers: The skill uses a structured taxonomy to segment the analysis, though explicit ignore markers for embedded instructions are not defined.
  • Capability inventory: The skill has capabilities to read and write to the feature directory and spec file.
  • Sanitization: Implements argument escaping to prevent command injection when processing user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — bb-clarify