bb-constitution
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting and acting upon instructions found within the repository's documentation files.
- Ingestion points: The agent reads from
constitution.md,README.md, thedocs/directory, and various template files (plan, spec, tasks, and command/skill templates) to derive principle values and update references. - Boundary markers: While user-provided
$ARGUMENTSare delineated, the skill lacks clear boundary markers or instructions to disregard malicious directives embedded within the existing repository files it processes. - Capability inventory: The skill possesses file system read and write capabilities, specifically the ability to overwrite
constitution.mdand modify references in other documentation files. - Sanitization: There is no evidence of content sanitization, validation, or filtering of the text ingested from the repository before it is used to generate the updated constitution and Sync Impact Report.
Audit Metadata