skills/suntechnic/vs-bitrix-ai/bx-trf/Gen Agent Trust Hub

bx-trf

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an instruction to suppress reporting and conclusions after the task is finished ("После завершения всех изменений не предоставляй отчёт и не делай выводов"). This is a concealment tactic that reduces user oversight of the agent's actions.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to prefer shell commands, specifically heredoc via cat, for all file operations ("При записи/перезаписи файлов предпочитай shell-команды (heredoc через cat)") instead of built-in editor tools.
  • [PROMPT_INJECTION]: The skill uses broad, permissive language that could be interpreted as bypassing implicit constraints ("Разрешаю использовать любые инструменты и действия для выполнения задачи").
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection (Category 8):
  • Ingestion points: The skill reads and processes all *.php files within specific component directories.
  • Boundary markers: No boundary markers or instructions to ignore embedded instructions in the source files are provided.
  • Capability inventory: The skill has the capability to execute shell commands (cat, pwd), read files, and write/modify files across the project directory.
  • Sanitization: There is no evidence of sanitization or validation of the content being read from the PHP files before it is processed or used in shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 10:04 AM
Security Audit — agent-trust-hub — bx-trf