lovstudio-bp-outline
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local initialization script,
scripts/init_bp.py. This script handles workspace setup, directory creation, and template rendering. It includes security safeguards that prevent the tool from writing to critical system directories or the root of the user's home directory.- [PROMPT_INJECTION]: The skill is designed to process various external data sources, including project documentation and websites. While this creates an attack surface for indirect prompt injection, the risk is mitigated by the skill's mandatory workflow, which requires the agent to verify all claims against an 'evidence ledger' and explicitly categorize them as facts, inferences, or assumptions.
Audit Metadata