bc-performance

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to perform web searches and fetch documentation to guide its optimization tasks. This creates a surface for indirect prompt injection attacks if the retrieved content contains malicious instructions designed to manipulate the agent.
  • Ingestion points: WebSearch and WebFetch tools are used to ingest external data from the web as instructed in SKILL.md.
  • Boundary markers: Absent. The skill lacks instructions to treat external data as untrusted or to ignore embedded commands within fetched content.
  • Capability inventory: The skill has access to Bash, Write, and Edit tools as defined in the frontmatter of SKILL.md, which represents a significant impact if an injection occurs.
  • Sanitization: Absent. The skill does not define any validation or sanitization for data fetched from the web.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM