talon
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive system monitoring using standard infrastructure tools including kubectl, docker, colima, and launchctl to verify the status of containers and services.
- [DYNAMIC_EXECUTION]: Supports user-defined script probes through a configuration file (~/.joelclaw/talon/services.toml) which are executed via the shell to provide extensible health checking.
- [PERSISTENCE]: The skill documents its own LaunchAgent and LaunchDaemon configurations, which are necessary for the watchdog to remain active across system restarts.
- [REMOTE_CODE_EXECUTION]: Automated scanners flagged a curl-to-python pipe. Analysis confirms the command (curl -sS http://127.0.0.1:9999/health | python3 -m json.tool) targets a local loopback address for the purpose of formatting JSON diagnostic output and is not a remote code execution threat.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from infrastructure logs and Kubernetes API responses. While this represents a potential attack surface, the risk is low as the skill follows a predefined state machine and uses the data for health classification rather than general reasoning.
Audit Metadata