ops-buzz
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.run()insrc/ops_buzz/cli.pyto execute thebuzzcommand-line utility. The path to the binary can be customized via theBUZZ_BINenvironment variable. This is used for all core functions including sending, searching, and retrieving messages from the relay. - [INDIRECT_PROMPT_INJECTION]: The
ask-agentandrender-messagecommands ingest JSON data to generate Markdown content intended for AI agents. This creates a surface where untrusted data from other skills or external sources could influence agent behavior. - Ingestion points: The
--inputargument insrc/ops_buzz/cli.pyreads JSON files containing titles, bodies, and prompts. - Boundary markers: The rendered output in
BuzzMessage.to_markdownandAgentRequest.to_markdowndoes not use specific delimiters to isolate external content from agent instructions. - Capability inventory: The skill can execute shell commands (
buzz) and performs file read/write operations. - Sanitization: Input is validated against dataclass schemas and type-checked during JSON loading.
- [CREDENTIALS_UNSAFE]: The skill is designed to handle sensitive Nostr private keys (
BUZZ_PRIVATE_KEY) for NIP-98 request signing. Therun.shscript automatically loads these and other environment variables from a.envfile located in the repository root, which is a standard configuration pattern.
Audit Metadata