bug-bounty-validation
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is an instructional framework composed of Markdown files. It does not contain any executable scripts, binaries, or tool configurations that could lead to unauthorized actions.
- [NO_CODE]: There are no code files (e.g., .py, .js, .sh) or scripts embedded within the skill. The logic is handled through natural language instructions for the AI agent.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill defines inputs for vulnerability metadata but lacks any network-capable tools or commands (e.g., curl, wget) to transmit this data to external endpoints.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection by ingesting untrusted data through variables such as BV_FINDING, BV_POC_STEPS, and BV_PROGRAM_SCOPE_URL (SKILL.md). There are no explicit boundary markers or sanitization logic present to delimit this data. However, the capability inventory for this skill is empty (no tools or script execution), meaning there are no exploitable functions available to an attacker.
Audit Metadata