fnox-configuration
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill documentation explicitly references sensitive filesystem paths such as
~/.config/fnox/keys/identity.txtand~/.ssh/age-identity.txtfor storing private encryption keys. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from project configuration files which may come from untrusted sources. Ingestion points: Processes
fnox.toml,fnox.local.toml, and external imports likeshared-secrets.toml. Boundary markers: No delimiters or isolation warnings are implemented for configuration values. Capability inventory: The skill utilizesBash,Read,Write, andEdittools. Sanitization: There is no mention of sanitizing or validating configuration values before they are used in commands or logic.
Audit Metadata