skills/tonone-ai/tonone/apex-recon/Gen Agent Trust Hub

apex-recon

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses routine shell and Git commands (such as ls -la, git log, and git status) to inspect the local workspace and repository history. These commands are standard for project orientation and do not involve privilege escalation or dangerous parameters.
  • [DATA_EXFILTRATION]: While the skill reads project configuration files and Git remote URLs, which can contain sensitive metadata, there is no evidence of the collected data being transmitted to external servers. The instructions are focused on presenting an assessment to the user or generating a local report.
  • [PROMPT_INJECTION]: The skill scans files like README.md and source code for comments (e.g., TODO/FIXME). Although these files are untrusted and could contain indirect prompt injection attempts, the skill is configured to summarize and inventory these findings rather than execute instructions found within them.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — apex-recon