bugcrowd-reporting
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown instructions and templates without any executable code, scripts, or package dependencies.
- [SAFE]: The content focuses on ethical security research practices, providing templates for rebutting out-of-scope closures and justifying severity overrides on the Bugcrowd platform. It includes hygiene recommendations such as account state restoration and session rotation.
- [INDIRECT_PROMPT_INJECTION]: The skill defines templates that interpolate external data, such as submission IDs and endpoint names. While this represents a surface for data ingestion, the skill lacks any executable tools or network capabilities that could be exploited by injected instructions.
- Ingestion points: Data provided in report fields (e.g., submission IDs, endpoint names).
- Boundary markers: Templates use Markdown headers and structural delimitation.
- Capability inventory: None detected.
- Sanitization: Not explicitly present, but output is restricted to human-readable Markdown.
- [EXTERNAL_DOWNLOADS]: References are made to the Bugcrowd platform and the Vulnerability Rating Taxonomy (VRT), which are well-known industry resources. No automated downloads or network requests are performed by the skill.
Audit Metadata