bonsai-impl-clash

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate technical resource for BIM coordination. No malicious code, obfuscation, or unauthorized network operations were detected.
  • [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by ingesting data from external sources. (1) Ingestion points: Data enters via IFC, JSON, and BCF file loaders. (2) Boundary markers: No delimiters are present for metadata. (3) Capability inventory: The skill can read/write files and manipulate the viewport. (4) Sanitization: No explicit sanitization of BIM data is shown.
  • [EXTERNAL_DOWNLOADS]: No patterns for remote code execution or external downloads were found. All operations are local.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:31 PM