bb-implement

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands (e.g., git rev-parse) to determine the repository state and project configuration.
  • [COMMAND_EXECUTION]: It is designed to interpret and execute an implementation plan defined in tasks.md, which involves running various setup and development tasks.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes and follows instructions from external data files.
  • Ingestion points: Reads data from tasks.md, plan.md, data-model.md, research.md, quickstart.md, and the contracts/ directory.
  • Boundary markers: The instructions do not define delimiters or specific safety prompts to prevent the agent from obeying instructions embedded within these files.
  • Capability inventory: The skill has the capability to write files (e.g., creating .gitignore, .dockerignore), read various project files, and execute shell-based implementation tasks.
  • Sanitization: There is no evidence of sanitization or validation of the content read from implementation documents before they are used to guide the agent's actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — bb-implement