bugcrowd-reporting

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown instructions and templates without any executable code, scripts, or package dependencies.
  • [SAFE]: The content focuses on ethical security research practices, providing templates for rebutting out-of-scope closures and justifying severity overrides on the Bugcrowd platform. It includes hygiene recommendations such as account state restoration and session rotation.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines templates that interpolate external data, such as submission IDs and endpoint names. While this represents a surface for data ingestion, the skill lacks any executable tools or network capabilities that could be exploited by injected instructions.
  • Ingestion points: Data provided in report fields (e.g., submission IDs, endpoint names).
  • Boundary markers: Templates use Markdown headers and structural delimitation.
  • Capability inventory: None detected.
  • Sanitization: Not explicitly present, but output is restricted to human-readable Markdown.
  • [EXTERNAL_DOWNLOADS]: References are made to the Bugcrowd platform and the Vulnerability Rating Taxonomy (VRT), which are well-known industry resources. No automated downloads or network requests are performed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:31 AM
Security Audit — agent-trust-hub — bugcrowd-reporting