atona
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill coordinates various activities by delegating tasks to a collection of specialist tools, such as
alagafor coding,iwadifor research, andarchitectfor system structure. This orchestration of sub-agents and tools is central to its planning and delivery function.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests requirements from external documents and research retrieved viaiwadi. This creates a theoretical surface where malicious instructions embedded in those sources could attempt to influence the agent's planning. However, the skill provides mitigation through a mandatory human-readable HTML plan, which ensures user oversight and approval of the initiative's direction.\n- [SAFE]: The skill maintains workflow continuity by persisting initiative state in the local.qp/atona/directory, which is a standard practice for context management and does not involve unauthorized data exposure.
Audit Metadata