skills/quantipixels/skills/atona/Gen Agent Trust Hub

atona

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill coordinates various activities by delegating tasks to a collection of specialist tools, such as alaga for coding, iwadi for research, and architect for system structure. This orchestration of sub-agents and tools is central to its planning and delivery function.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests requirements from external documents and research retrieved via iwadi. This creates a theoretical surface where malicious instructions embedded in those sources could attempt to influence the agent's planning. However, the skill provides mitigation through a mandatory human-readable HTML plan, which ensures user oversight and approval of the initiative's direction.\n- [SAFE]: The skill maintains workflow continuity by persisting initiative state in the local .qp/atona/ directory, which is a standard practice for context management and does not involve unauthorized data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:17 PM
Security Audit — agent-trust-hub — atona