tokenpass

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references source code and binary releases from the author's official GitHub repositories (github.com/b-open-io/tokenpass-server and github.com/b-open-io/tokenpass-desktop).
  • [COMMAND_EXECUTION]: Provides standard developer commands for cloning repositories and managing dependencies using bun (e.g., bun install, bun dev).
  • [DATA_EXPOSURE]: The documentation describes the local storage of encrypted cryptographic data in the ~/.tokenpass/ directory, which is necessary for the functional purpose of the identity server.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for handling user data such as passwords and messages through local REST API calls.
  • Ingestion points: Data is ingested via POST request bodies in the /api/login, /api/register, and /api/sign endpoints (SKILL.md).
  • Boundary markers: Interaction examples consistently use JSON structures to delimit user input from control logic.
  • Capability inventory: The skill facilitates local file system storage (~/.tokenpass/) and subprocess execution for environment setup (git, bun) (SKILL.md).
  • Sanitization: Standard JSON encoding is applied to user-provided strings before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 05:13 PM