bug-bounty-workflow
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown instructions and YAML metadata. No executable scripts, binaries, or automated tools are included in the skill package.
- [INDIRECT_PROMPT_INJECTION]: The workflow involves ingesting untrusted external data, such as program briefs and OSINT results, which constitutes an attack surface for indirect prompt injection. However, the risk is mitigated by explicit instructions to follow program rules and the absence of automated execution logic.
- Ingestion points: Program briefs from platforms like HackerOne/Bugcrowd, passive OSINT data, and public vulnerability disclosures.
- Boundary markers: None specified for external data ingestion.
- Capability inventory: The skill mentions testing for RCE, SSRF, and IDOR, but does not provide scripts to execute these tests; it serves as a high-level guide for the agent.
- Sanitization: The quality bar instructions require redacting secrets from logs and reports.
Audit Metadata