fnox-providers

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read, write, and configure secret management through fnox.toml files. These configuration files represent an ingestion point for untrusted data. If these files were to contain malicious instructions, the agent's capabilities—which include file system access and shell command execution—could be leveraged to perform unintended actions.
  • Ingestion points: fnox.toml, fnox.local.toml, and environment variables referenced in configurations.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined for the configuration data.
  • Capability inventory: The skill utilizes Read, Write, Edit, Bash, Grep, and Glob tools, providing significant access to the local environment.
  • Sanitization: No explicit sanitization or validation of the configuration file content is mentioned before processing.
  • [CREDENTIALS_UNSAFE]: The skill interacts with and references sensitive file paths intended for credential storage, specifically ~/.config/fnox/keys/identity.txt and ~/.aws/credentials. While the instructions appropriately advise using these paths to avoid hardcoding secrets in version-controlled files, the interaction with these specific locations is a known pattern for sensitive data access. Additionally, the skill contains standard documentation placeholders for AWS credentials (AKIAIOSFODNN7EXAMPLE) within an anti-pattern example section.
  • [COMMAND_EXECUTION]: The skill provides numerous examples and instructions for executing shell commands using the Bash tool, such as age-keygen, fnox set, and fnox provider test. While these are functional requirements for the skill, the reliance on shell execution increases the impact of potential command injection if input from configuration files is not handled securely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:22 PM
Security Audit — agent-trust-hub — fnox-providers