bc-testing

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions rely on the agent fetching external content from the web, creating a potential surface for indirect prompt injection where malicious instructions could be retrieved and executed.
  • Ingestion points: The skill explicitly instructs the agent to use WebSearch and WebFetch in SKILL.md to obtain live documentation and testing guidance from external websites.
  • Boundary markers: The skill does not provide clear delimiters or protective instructions (e.g., "treat the following as data only") to prevent the agent from following instructions that might be embedded in the fetched documentation.
  • Capability inventory: The skill is configured with broad permissions, including Bash, Write, Edit, and Read, which could be exploited if an external source successfully injects malicious commands into the agent's context.
  • Sanitization: There are no mechanisms described or implemented to sanitize or validate the content retrieved from external sources before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM