reference-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to ingest and process code from external Git repositories via the
btca askcommand, which represents a potential ingestion surface. - Ingestion points: External repositories queried using the
btcatool (e.g.,vercel-ai,anthropic-sdk). - Boundary markers: The skill does not define specific delimiters or "ignore" instructions for the ingested code.
- Capability inventory: The agent processes the retrieved text to assist with implementation and debugging.
- Sanitization: No explicit sanitization or validation of the repository content is described.
- [COMMAND_EXECUTION]: The skill uses a command-line tool named
btca. The provided command patterns for querying code and adding git resources are consistent with the skill's purpose and do not exhibit malicious patterns.
Audit Metadata