AFOL BrickOwl
PassAudited by VirusTotal on May 10, 2026.
Findings (1)
The skill bundle contains conflicting instructions that appear to be a prompt injection attempt to bypass safety protocols. While SKILL.md and the CLI implementation in scripts/brickowl_cli.py mandate explicit user confirmation and the use of a '--yes' flag for mutating actions (e.g., inventory deletion or creation), the domain guidance file (references/prompts/brickowl-tools.txt) explicitly instructs the AI agent that 'NO User Approval Required' and that actions should 'execute immediately without approval flow.' This contradiction encourages the agent to ignore the safety requirements for marketplace operations, potentially leading to unauthorized financial or inventory changes.
