skills/oakoss/agent-skills/hono/Gen Agent Trust Hub

hono

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied code snippets and application requirements to provide Hono-specific implementations, creating a surface for indirect prompt injection.
  • Ingestion points: User-provided code and architectural descriptions in the context of building APIs (SKILL.md).
  • Boundary markers: The skill does not define specific delimiters for separating untrusted user code from system instructions.
  • Capability inventory: The skill utilizes the agent's default environment capabilities, including file system access and shell execution for project setup (references/adapters.md).
  • Sanitization: Relies on the platform's default LLM safety guardrails.
  • [EXTERNAL_DOWNLOADS]: The documentation contains commands for installing the Hono framework and its adapters from official registries (e.g., npm install hono, npm create hono@latest, deno run -A npm:create-hono@latest). It also references Deno modules from https://deno.land/x/hono. These are standard, well-known development resources for this framework.
  • [CREDENTIALS_UNSAFE]: Educational examples in the middleware documentation (references/middleware.md) include hardcoded dummy credentials such as password: 'secret', token: 'my-secret-token', and secret: 'it-is-very-secret'. These are clearly illustrative placeholders for developers and do not represent actual secrets within the skill's operational code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:50 AM
Security Audit — agent-trust-hub — hono