byterover-audit

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute several commands using the ByteRover CLI tool (brv), including brv status, brv query, brv curate, and brv curate view. These tools are used for their intended purpose within the ByteRover ecosystem to manage and audit knowledge base entries.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests and processes content from local project files that could contain malicious instructions. 1. Ingestion points: The agent reads various local files including package.json, requirements.txt, .env.example, and source code files in Phases 2 and 4. 2. Boundary markers: No delimiters or ignore instructions are specified when the agent processes these files. 3. Capability inventory: The agent can execute commands (brv curate, brv query) based on the information it extracts from the files. 4. Sanitization: There are no instructions for sanitizing or validating the content read from the files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:13 AM
Security Audit — agent-trust-hub — byterover-audit