tokener
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill revolves around the execution of the
tokenerCLI tool and its various subcommands. The instructions guide the agent on how to use search, auth, and agent harnesses to interact with the Tokener Gateway. - [EXTERNAL_DOWNLOADS]: The commands
tokener skill installandtokener updateallow for fetching and installing external components or binary updates fromconsole.tokener.dev. These operations are protected by instructions requiring user confirmation or dry-runs. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved from the Tokener command catalog and search results.
- Ingestion points: Command metadata and search results from
tokener searchandtokener commands show, including fields likenotesandknown_errors(referenced inreferences/catalog.md). - Boundary markers: The skill encourages the use of JSON output (
--json) to help the agent parse responses reliably, though it lacks explicit delimiters for instructions embedded in data. - Capability inventory: The agent can execute state-changing CLI commands, manage API keys, and install new skills.
- Sanitization: The instructions require the agent to inspect the
mutationtype and perform a--dry-runor seek user confirmation for any operation that is not a simple 'read'. - [CREDENTIALS_UNSAFE]: The skill provides guidelines for handling Personal Access Tokens (PATs) and API keys. It explicitly instructs the agent to treat these as credentials and avoid writing them to logs or shell history, demonstrating a secure handling pattern.
- [DYNAMIC_EXECUTION]: The
tokener agentcommand launches external harnesses (e.g., claude, codex), and the execution process fetches aruntime_schemawhich dynamically defines the command's behavior at runtime.
Audit Metadata