bc-security
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use WebSearch and WebFetch to retrieve live security documentation from external sources. This content is processed in an environment with high-privilege tools like Bash and Write.
- Ingestion points: Documentation is retrieved from the web via WebSearch and WebFetch (SKILL.md).
- Boundary markers: No specific delimiters or warnings for the agent to ignore instructions embedded in the fetched content are provided.
- Capability inventory: The skill environment includes Bash, Write, and Edit tools.
- Sanitization: The instructions do not specify sanitization or validation of the fetched external content.
- [NO_CODE]: The skill consists exclusively of markdown documentation and instructions, without providing any scripts, executables, or configuration files.
Audit Metadata