bb-constitution

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting and acting upon instructions found within the repository's documentation files.
  • Ingestion points: The agent reads from constitution.md, README.md, the docs/ directory, and various template files (plan, spec, tasks, and command/skill templates) to derive principle values and update references.
  • Boundary markers: While user-provided $ARGUMENTS are delineated, the skill lacks clear boundary markers or instructions to disregard malicious directives embedded within the existing repository files it processes.
  • Capability inventory: The skill possesses file system read and write capabilities, specifically the ability to overwrite constitution.md and modify references in other documentation files.
  • Sanitization: There is no evidence of content sanitization, validation, or filtering of the text ingested from the repository before it is used to generate the updated constitution and Sync Impact Report.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — bb-constitution