1c-bitrix-cms
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local shell scripts, specifically
detect-bitrix.shandcheck-conventions.sh, located in the../../shared/scripts/directory. These are used for read-only environmental diagnostics and linting of the project files to ensure they adhere to defined standards. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze existing project files, configurations (such as
.settings.php), and database content from a Bitrix installation. While this processes external project data which could theoretically contain malicious instructions, the skill includes explicit references to security conventions and automated validation scripts (check-conventions.sh) to mitigate these risks. - [EXTERNAL_DOWNLOADS]: The documentation references checking the author's repository at
github.com/vrtalex/1c-bitrix-cms-skillfor version updates. As this repository belongs to the identified vendor, it is treated as a safe resource.
Audit Metadata