bb-local-toolkit

Fail

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download the skill file and multiple security tools (such as arjun, paramspider, sqlmap) from external sources including GitHub and various package registries.
  • [COMMAND_EXECUTION]: Provides detailed command-line instructions for performing offensive security tasks, reconnaissance, and exploitation, which requires the agent to execute arbitrary commands on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external target data (source code, API responses, web content) which introduces an attack surface for indirect prompt injection. 1. Ingestion points: Processes data retrieved via katana, waybackurls, and curl from arbitrary target URLs in SKILL.md. 2. Boundary markers: Lacks explicit instructions for the agent to treat target-derived data as untrusted or to use clear delimiters. 3. Capability inventory: Includes wide access to system shell, network operations, and file system modification through the recommended toolset in SKILL.md. 4. Sanitization: No evidence of sanitizing external data before it is processed by the agent.
  • [PROMPT_INJECTION]: Contains strong imperative language and behavioral overrides such as 'CRITICAL RULES' and 'STOP. Do not write.' designed to constrain agent behavior and potentially bypass default reasoning processes.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — bb-local-toolkit