bb-tasks

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from user arguments and external files (e.g., plan.md, spec.md) to generate task descriptions. It lacks explicit delimiters or instructions to ignore potential malicious prompts embedded within these source files, creating a surface for indirect prompt injection.
  • Ingestion points: Processes user input via $ARGUMENTS and reads multiple design files (plan.md, spec.md, etc.) from the feature directory.
  • Boundary markers: No explicit delimiters or boundary markers are used when interpolating content into the generation workflow.
  • Capability inventory: Performs file-system read operations on project documentation and write operations to create tasks.md. No network access or subprocess execution is defined in the skill.
  • Sanitization: No evidence of input sanitization or validation of the ingested file content.
  • [SAFE]: The skill's operations are confined to reading local project documentation and writing a structured markdown file. It does not perform network operations, execute arbitrary shell commands, or request elevated privileges. The references to local template paths (~/.bb-skills/) are consistent with the stated development workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 05:49 AM
Security Audit — agent-trust-hub — bb-tasks