bb-local-toolkit
Fail
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download the skill file and multiple security tools (such as
arjun,paramspider,sqlmap) from external sources including GitHub and various package registries. - [COMMAND_EXECUTION]: Provides detailed command-line instructions for performing offensive security tasks, reconnaissance, and exploitation, which requires the agent to execute arbitrary commands on the host system.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external target data (source code, API responses, web content) which introduces an attack surface for indirect prompt injection. 1. Ingestion points: Processes data retrieved via
katana,waybackurls, andcurlfrom arbitrary target URLs inSKILL.md. 2. Boundary markers: Lacks explicit instructions for the agent to treat target-derived data as untrusted or to use clear delimiters. 3. Capability inventory: Includes wide access to system shell, network operations, and file system modification through the recommended toolset inSKILL.md. 4. Sanitization: No evidence of sanitizing external data before it is processed by the agent. - [PROMPT_INJECTION]: Contains strong imperative language and behavioral overrides such as 'CRITICAL RULES' and 'STOP. Do not write.' designed to constrain agent behavior and potentially bypass default reasoning processes.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata