token-build

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructs the agent to execute local Python scripts, specifically scripts/validate_tokens.py and scripts/contrast.py, to verify token integrity and accessibility standards during the build process.
  • [DYNAMIC_EXECUTION]: The instructions suggest creating and executing 'a small custom script' modeled on existing validation logic, which constitutes dynamic code generation and execution to handle specific platform requirements.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from tokens/.json files, which introduces a potential attack surface for indirect prompt injection. 1. Ingestion points: Data is read from tokens/.json files. 2. Boundary markers: The instructions lack explicit delimiters or 'ignore' warnings for the content within the JSON files. 3. Capability inventory: The agent can perform file system writes and execute shell scripts. 4. Sanitization: The skill uses a validation script (scripts/validate_tokens.py) to check for unresolved aliases before final generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 05:32 PM
Security Audit — agent-trust-hub — token-build