bb-plan
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources including
FEATURE_SPEC,user-stories.md, and the user-supplied$ARGUMENTSwithout implementing boundary markers or explicit instructions to ignore embedded commands. This creates a surface for indirect prompt injection where instructions hidden in specifications or user stories could influence the agent's research and planning decisions. - Ingestion points:
FEATURE_SPEC,constitution.md,buildbetter-context.md,buildbetter-context.json,user-stories.md, and$ARGUMENTS. - Boundary markers: None detected; data is parsed and used directly to fill templates.
- Capability inventory: Reading project files, writing new markdown files (
research.md,data-model.md,quickstart.md), and generating tasks for subsequent agent execution. - Sanitization: None detected.
- [DATA_EXFILTRATION]: The skill accesses sensitive project context files and configuration stored in the user's home directory (
~/.bb-skills/). While this appears to be the intended function for the BuildBetter workflow, it grants the agent access to potentially private architectural decisions and customer pain points.
Audit Metadata