1c-bitrix-cms-content

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run a local utility script check-conventions.sh and execute PHP code via CLI or administrative interfaces. These operations are legitimate and necessary for the stated purpose of managing a Bitrix CMS project.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with existing project files and handles form submissions, which represent an attack surface for indirect prompt injection. Ingestion points: Project introspection via 01-introspect-project.md and feedback form data via 10-feedback-form.md. Boundary markers: No specific boundary markers or 'ignore' instructions are explicitly provided in the skill text. Capability inventory: The skill allows for PHP execution and file system modifications within the /local directory. Sanitization: The skill relies on an external convention check script (check-conventions.sh) to perform manual and automated reviews before finalizing tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 07:42 PM
Security Audit — agent-trust-hub — 1c-bitrix-cms-content