bc-security

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use WebSearch and WebFetch to retrieve live security documentation from external sources. This content is processed in an environment with high-privilege tools like Bash and Write.
  • Ingestion points: Documentation is retrieved from the web via WebSearch and WebFetch (SKILL.md).
  • Boundary markers: No specific delimiters or warnings for the agent to ignore instructions embedded in the fetched content are provided.
  • Capability inventory: The skill environment includes Bash, Write, and Edit tools.
  • Sanitization: The instructions do not specify sanitization or validation of the fetched external content.
  • [NO_CODE]: The skill consists exclusively of markdown documentation and instructions, without providing any scripts, executables, or configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM