1c-bitrix-cms-security

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external project code and configurations. Maliciously crafted content within these project files could potentially attempt to influence the agent's behavior or output during the security audit process.
  • Ingestion points: The skill processes files within a user-provided project directory through the static analysis tool.
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" warnings for the external data being processed.
  • Capability inventory: The skill utilizes a local shell script (check-conventions.sh) and has the capability to read and analyze project files.
  • Sanitization: No explicit sanitization or filtering of the external project content is mentioned before the analysis is performed.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local shell script, ../../shared/scripts/check-conventions.sh, to perform static security checks on a project directory. This is a functional capability used for the skill's stated purpose of auditing security conventions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 07:42 PM
Security Audit — agent-trust-hub — 1c-bitrix-cms-security