bc-channels

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential surface for indirect prompt injection as it is designed to ingest external data from documentation websites.
  • Ingestion points: The skill instructs the agent to use WebFetch to retrieve content from developer.bigcommerce.com within SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands in the fetched documentation are provided.
  • Capability inventory: The agent is permitted to use Bash, Write, and Edit tools as defined in the skill configuration.
  • Sanitization: The skill does not define methods for sanitizing or validating the content retrieved from external documentation sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM