reference-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to ingest and process code from external Git repositories via the btca ask command, which represents a potential ingestion surface.
  • Ingestion points: External repositories queried using the btca tool (e.g., vercel-ai, anthropic-sdk).
  • Boundary markers: The skill does not define specific delimiters or "ignore" instructions for the ingested code.
  • Capability inventory: The agent processes the retrieved text to assist with implementation and debugging.
  • Sanitization: No explicit sanitization or validation of the repository content is described.
  • [COMMAND_EXECUTION]: The skill uses a command-line tool named btca. The provided command patterns for querying code and adding git resources are consistent with the skill's purpose and do not exhibit malicious patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — reference-sdk