bb-specify
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands such as "git fetch", "git ls-remote", and "git branch" to manage project repository states. These commands rely on a feature name derived from the user's natural language input.
- [PROMPT_INJECTION]: The skill processes untrusted user input through the "$ARGUMENTS" variable to drive its logic, which introduces a surface for indirect prompt injection.
- Ingestion points: Feature descriptions provided by the user in "SKILL.md" are the primary source of untrusted data.
- Boundary markers: No specific delimiters or safety instructions are used to isolate user input from the skill's logic.
- Capability inventory: The skill possesses the ability to execute Git commands, create file system structures, and write files.
- Sanitization: There is no evidence of validation or sanitization of the user input before it is used to generate branch names or specification content.
Audit Metadata