bc-testing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions rely on the agent fetching external content from the web, creating a potential surface for indirect prompt injection where malicious instructions could be retrieved and executed.
- Ingestion points: The skill explicitly instructs the agent to use
WebSearchandWebFetchinSKILL.mdto obtain live documentation and testing guidance from external websites. - Boundary markers: The skill does not provide clear delimiters or protective instructions (e.g., "treat the following as data only") to prevent the agent from following instructions that might be embedded in the fetched documentation.
- Capability inventory: The skill is configured with broad permissions, including
Bash,Write,Edit, andRead, which could be exploited if an external source successfully injects malicious commands into the agent's context. - Sanitization: There are no mechanisms described or implemented to sanitize or validate the content retrieved from external sources before the agent processes it.
Audit Metadata