bb-implement
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands (e.g.,
git rev-parse) to determine the repository state and project configuration. - [COMMAND_EXECUTION]: It is designed to interpret and execute an implementation plan defined in
tasks.md, which involves running various setup and development tasks. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes and follows instructions from external data files.
- Ingestion points: Reads data from
tasks.md,plan.md,data-model.md,research.md,quickstart.md, and thecontracts/directory. - Boundary markers: The instructions do not define delimiters or specific safety prompts to prevent the agent from obeying instructions embedded within these files.
- Capability inventory: The skill has the capability to write files (e.g., creating
.gitignore,.dockerignore), read various project files, and execute shell-based implementation tasks. - Sanitization: There is no evidence of sanitization or validation of the content read from implementation documents before they are used to guide the agent's actions.
Audit Metadata