1c-bitrix-cms

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local shell scripts, specifically detect-bitrix.sh and check-conventions.sh, located in the ../../shared/scripts/ directory. These are used for read-only environmental diagnostics and linting of the project files to ensure they adhere to defined standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze existing project files, configurations (such as .settings.php), and database content from a Bitrix installation. While this processes external project data which could theoretically contain malicious instructions, the skill includes explicit references to security conventions and automated validation scripts (check-conventions.sh) to mitigate these risks.
  • [EXTERNAL_DOWNLOADS]: The documentation references checking the author's repository at github.com/vrtalex/1c-bitrix-cms-skill for version updates. As this repository belongs to the identified vendor, it is treated as a safe resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 07:41 PM
Security Audit — agent-trust-hub — 1c-bitrix-cms