epf-bsp-add-command

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured templates and instructions for the agent to modify local BSL source files within a 1C project. It automates boilerplate tasks for the Standard Subsystems Library (BSP) framework.
  • [SAFE]: The skill's environment is restricted to local file manipulation tools (Read, Edit, Glob, Grep). No external network requests, remote script execution, or dependency installations are performed.
  • [SAFE]: Analysis of potential indirect prompt injection surface: 1. Ingestion points: User-supplied parameters (ProcessorName, Идентификатор, Представление) and local project files (ObjectModule.bsl). 2. Boundary markers: Absent. 3. Capability inventory: The Edit tool allows writing to any project file. 4. Sanitization: Absent. While this creates a surface where malicious input could influence code generation, it is a standard characteristic of development automation tools and is considered safe in this context.
  • [SAFE]: No evidence of prompt injection, obfuscation, persistence mechanisms, or credential harvesting was found in the instructions or templates.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 11:10 AM
Security Audit — agent-trust-hub — epf-bsp-add-command