skills/celeroncoder/skills/bb-cli/Gen Agent Trust Hub

bb-cli

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The bb CLI provides extensive capabilities for executing shell commands and scripts through several features:
  • bb terminal create allows spawning persistent PTY sessions for long-running processes like development servers and database consoles.
  • bb automation create with the --script or --script-file flags allows the creation of automated tasks that execute arbitrary code at scheduled intervals.
  • bb plugin run executes subcommands contributed by installed plugins, which are described as full-trust code.
  • [REMOTE_CODE_EXECUTION]: The skill documents a plugin and marketplace system that facilitates the installation of external code:
  • bb plugin install supports installing from Git repositories, NPM packages, and local paths. The documentation explicitly states that "plugins are full-trust code."
  • bb marketplace add allows users to register third-party marketplaces from HTTPS manifest URLs, which can then be used to discover and install additional plugins.
  • [DYNAMIC_EXECUTION]: The tool includes a workflow engine and a custom agent registration system involving dynamic code:
  • bb workflows run executes durable, provider-independent JavaScript for task orchestration.
  • Custom ACP agents can be registered in the config.json file, allowing the execution of locally configured commands as agent backends.
  • [PERSISTENCE]: The automations plugin allows for establishing persistence on a host via cron-scheduled tasks:
  • Users can create scheduled jobs using standard 5-field cron expressions (--cron) that trigger either agent-based prompts or script-based executions.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection as it is designed to process external and potentially untrusted data:
  • Ingestion points: The agent reads project files (bb project content), task attachments (bb tasks attachment get), pull request data (bb environment pull-request show), and external documentation (bb docs pull).
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings when processing this data.
  • Capability inventory: The agent has access to powerful tools across all scripts, including file writes (bb file write), plugin installation, network port exposure (bb connect expose), and secret management (bb secret request).
  • Sanitization: No explicit sanitization or validation routines for external content are described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — bb-cli