find-token

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local bash script (tools/find-token.sh) which uses standard system utilities like head, base64, and cat to generate and store tokens.
  • [INDIRECT_PROMPT_INJECTION]: The script's JSON output includes fields such as command (e.g., "cat .hidden_token") and rbac permissions (e.g., "resources": ["secrets"]). While these are part of a mock analysis schema, they represent a surface where an agent might be influenced to take further actions based on the script's output content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 09:48 AM
Security Audit — agent-trust-hub — find-token