to-features
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
bdCLI tool for managing issues within the project's tracker. These commands are consistent with the skill's stated engineering workflow. - [PROMPT_INJECTION]: The skill processes untrusted input (plans/specs) to generate tasks. Ingestion points: user-provided documentation in SKILL.md. Boundary markers: absent. Capability inventory: issue creation and retrieval via the
bdtool. Sanitization: none specified. This represents a surface for indirect prompt injection where malicious input could influence task generation, though the impact is restricted to the issue tracker.
Audit Metadata