bb-cli
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The bb CLI provides extensive capabilities for executing shell commands and scripts through several features:
bb terminal createallows spawning persistent PTY sessions for long-running processes like development servers and database consoles.bb automation createwith the--scriptor--script-fileflags allows the creation of automated tasks that execute arbitrary code at scheduled intervals.bb plugin runexecutes subcommands contributed by installed plugins, which are described as full-trust code.- [REMOTE_CODE_EXECUTION]: The skill documents a plugin and marketplace system that facilitates the installation of external code:
bb plugin installsupports installing from Git repositories, NPM packages, and local paths. The documentation explicitly states that "plugins are full-trust code."bb marketplace addallows users to register third-party marketplaces from HTTPS manifest URLs, which can then be used to discover and install additional plugins.- [DYNAMIC_EXECUTION]: The tool includes a workflow engine and a custom agent registration system involving dynamic code:
bb workflows runexecutes durable, provider-independent JavaScript for task orchestration.- Custom ACP agents can be registered in the
config.jsonfile, allowing the execution of locally configured commands as agent backends. - [PERSISTENCE]: The automations plugin allows for establishing persistence on a host via cron-scheduled tasks:
- Users can create scheduled jobs using standard 5-field cron expressions (
--cron) that trigger either agent-based prompts or script-based executions. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection as it is designed to process external and potentially untrusted data:
- Ingestion points: The agent reads project files (
bb project content), task attachments (bb tasks attachment get), pull request data (bb environment pull-request show), and external documentation (bb docs pull). - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings when processing this data.
- Capability inventory: The agent has access to powerful tools across all scripts, including file writes (
bb file write), plugin installation, network port exposure (bb connect expose), and secret management (bb secret request). - Sanitization: No explicit sanitization or validation routines for external content are described in the instructions.
Audit Metadata