bb-review
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill follows its stated purpose of facilitating feature reviews within a local project environment.
- [DATA_EXPOSURE]: The skill reads project documentation (
spec.md,plan.md,tasks.md) and source code to perform its analysis. This behavior is restricted to the local workspace and does not involve accessing sensitive system credentials or environment variables. - [PROMPT_INJECTION]: The skill processes user arguments and external documentation files. Although this technically creates a surface for indirect prompt injection, the risk is negligible as the skill lacks dangerous capabilities such as network access or shell command execution to be exploited.
- [COMMAND_EXECUTION]: The instructions recommend Playwright validation to the user based on certain conditions but do not attempt to execute any shell commands or automated tests directly.
Audit Metadata