bb-review

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill follows its stated purpose of facilitating feature reviews within a local project environment.
  • [DATA_EXPOSURE]: The skill reads project documentation (spec.md, plan.md, tasks.md) and source code to perform its analysis. This behavior is restricted to the local workspace and does not involve accessing sensitive system credentials or environment variables.
  • [PROMPT_INJECTION]: The skill processes user arguments and external documentation files. Although this technically creates a surface for indirect prompt injection, the risk is negligible as the skill lacks dangerous capabilities such as network access or shell command execution to be exploited.
  • [COMMAND_EXECUTION]: The instructions recommend Playwright validation to the user based on certain conditions but do not attempt to execute any shell commands or automated tests directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — bb-review