toon

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides utility scripts for data format conversion and validation without any malicious logic. The conversion scripts in both Python and JavaScript are focused on format transformation and maintain a clear, non-suspicious structure.
  • [EXTERNAL_DOWNLOADS]: The Node.js scripts rely on the @toon-format/toon package. This is an official project library associated with the TOON format described in the skill and originates from the project's own repository and registry entries.
  • [PROMPT_INJECTION]: The skill implements a data processing surface by converting external JSON and TOON files. While this creates an ingestion point for untrusted data, the scripts are designed as transformation utilities and do not show patterns of instruction overriding or safety bypass attempts. The ingestion points include the conversion and validation scripts (scripts/convert.js, scripts/convert.py, scripts/validate.py) which read content from the file system or standard input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 11:32 AM
Security Audit — agent-trust-hub — toon