skills/joelhooks/joelclaw/talon/Gen Agent Trust Hub

talon

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive system monitoring using standard infrastructure tools including kubectl, docker, colima, and launchctl to verify the status of containers and services.
  • [DYNAMIC_EXECUTION]: Supports user-defined script probes through a configuration file (~/.joelclaw/talon/services.toml) which are executed via the shell to provide extensible health checking.
  • [PERSISTENCE]: The skill documents its own LaunchAgent and LaunchDaemon configurations, which are necessary for the watchdog to remain active across system restarts.
  • [REMOTE_CODE_EXECUTION]: Automated scanners flagged a curl-to-python pipe. Analysis confirms the command (curl -sS http://127.0.0.1:9999/health | python3 -m json.tool) targets a local loopback address for the purpose of formatting JSON diagnostic output and is not a remote code execution threat.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from infrastructure logs and Kubernetes API responses. While this represents a potential attack surface, the risk is low as the skill follows a predefined state machine and uses the data for health classification rather than general reasoning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:22 PM
Security Audit — agent-trust-hub — talon