tokenpass
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references source code and binary releases from the author's official GitHub repositories (
github.com/b-open-io/tokenpass-serverandgithub.com/b-open-io/tokenpass-desktop). - [COMMAND_EXECUTION]: Provides standard developer commands for cloning repositories and managing dependencies using
bun(e.g.,bun install,bun dev). - [DATA_EXPOSURE]: The documentation describes the local storage of encrypted cryptographic data in the
~/.tokenpass/directory, which is necessary for the functional purpose of the identity server. - [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for handling user data such as passwords and messages through local REST API calls.
- Ingestion points: Data is ingested via POST request bodies in the
/api/login,/api/register, and/api/signendpoints (SKILL.md). - Boundary markers: Interaction examples consistently use JSON structures to delimit user input from control logic.
- Capability inventory: The skill facilitates local file system storage (
~/.tokenpass/) and subprocess execution for environment setup (git,bun) (SKILL.md). - Sanitization: Standard JSON encoding is applied to user-provided strings before processing.
Audit Metadata