tool-tracer

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEDATA_EXFILTRATIONCREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Internal Data Exposure]: The skill captures internal execution logs, including tool inputs and outputs, and saves them to a JSON file for download. This allows internal context to be exported from the agent's runtime environment.- [Credential and Token Handling]: The '--full' flag enables verbatim capture of all internal data, bypassing default redaction. If not restricted to authorized users, this could expose API tokens or credentials processed during the session.- [Authorization Governance]: The skill relies on external platform-level controls to restrict access to the sensitive '--full' command. Administrators should ensure appropriate access policies are in place.- [Indirect Prompt Injection Surface]: The skill processes user-supplied tasks (SKILL.md) and executes them using the agent's full capability set, including file-writing. The absence of explicit boundary markers or input sanitization creates a surface where untrusted data within a task could potentially influence the agent's execution or the generated trace.- [Resource Source Verification]: The skill metadata references an external repository rather than an official vendor-owned resource, which warrants verification of the source's provenance during the deployment process.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 11:56 PM
Security Audit — agent-trust-hub — tool-tracer