builderbot-code-skill

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for building chatbots that handle untrusted data. Ingestion points: ctx.body in SKILL.md and patterns.md. Boundary markers: Regex validation patterns shown in patterns.md. Capability inventory: Includes network requests (fetch), file management (provider.saveFile), and message dispatching (flowDynamic) as seen in patterns.md. Sanitization: Logic for validating inputs (e.g., email regex) is documented in patterns.md.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references several official BuilderBot packages (e.g., @builderbot/bot, @builderbot/provider-baileys) and plugins from the npm registry. These are standard, well-known dependencies for the framework's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:00 AM
Security Audit — agent-trust-hub — builderbot-code-skill