ops-buzz

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run() in src/ops_buzz/cli.py to execute the buzz command-line utility. The path to the binary can be customized via the BUZZ_BIN environment variable. This is used for all core functions including sending, searching, and retrieving messages from the relay.
  • [INDIRECT_PROMPT_INJECTION]: The ask-agent and render-message commands ingest JSON data to generate Markdown content intended for AI agents. This creates a surface where untrusted data from other skills or external sources could influence agent behavior.
  • Ingestion points: The --input argument in src/ops_buzz/cli.py reads JSON files containing titles, bodies, and prompts.
  • Boundary markers: The rendered output in BuzzMessage.to_markdown and AgentRequest.to_markdown does not use specific delimiters to isolate external content from agent instructions.
  • Capability inventory: The skill can execute shell commands (buzz) and performs file read/write operations.
  • Sanitization: Input is validated against dataclass schemas and type-checked during JSON loading.
  • [CREDENTIALS_UNSAFE]: The skill is designed to handle sensitive Nostr private keys (BUZZ_PRIVATE_KEY) for NIP-98 request signing. The run.sh script automatically loads these and other environment variables from a .env file located in the repository root, which is a standard configuration pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ops-buzz