bd-to-br-migration

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on standard shell utilities and custom bash scripts to automate the migration process. Specifically, the scripts find-bd-refs.sh and verify-migration.sh use grep and sort to identify and validate file contents, while instructions include using git add and git commit to manage repository changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process documentation files which can contain untrusted data, representing a surface for indirect prompt injection.
  • Ingestion points: The skill reads and processes the content of markdown files (e.g., AGENTS.md) across a filesystem using both the agent's file tools and provided search scripts.
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded within the documentation files being processed.
  • Capability inventory: The agent is granted Edit and Bash (via local scripts) capabilities to perform transformations and run verification tools.
  • Sanitization: The skill lacks explicit sanitization or validation of the input markdown file content before it is interpolated or processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 02:10 PM
Security Audit — agent-trust-hub — bd-to-br-migration