bb-skills-update

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the bb-skills update command to check for and apply updates to installed components. This is a core function for maintaining the local environment.
  • [EXTERNAL_DOWNLOADS]: The instructions suggest installing the bb-skills package from PyPI if it is missing. This package is the primary CLI for the vendor's platform.
  • [PROMPT_INJECTION]: The skill reads from a local manifest file, which creates a potential surface for indirect prompt injection if the file content is maliciously crafted.
  • Ingestion points: The file ~/.bb-skills/manifest.json is read to determine current versioning.
  • Boundary markers: There are no markers or delimiters used when the agent processes this file content.
  • Capability inventory: The skill has the ability to execute the bb-skills command-line utility.
  • Sanitization: The skill does not perform validation or sanitization on the data retrieved from the manifest file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — bb-skills-update