skills/tonone-ai/tonone/bind-recon/Gen Agent Trust Hub

bind-recon

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions do not contain any malicious patterns or security risks.
  • [COMMAND_EXECUTION]: The skill is configured with access to the Bash tool, which is intended for surveying local project artifacts during the reconnaissance phase. The prompt does not specify any dangerous or arbitrary commands.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes WebSearch and WebFetch to gather regulatory guidance from external sources, which is a core function of the reconnaissance workflow.
  • [PROMPT_INJECTION]: The skill identifies a workflow that ingests untrusted data from project files and the web. Ingestion points: local compliance artifacts and external regulatory guidance (Step 1). Boundary markers: None. Capability inventory: Bash, Write, WebFetch, Read (frontmatter). Sanitization: None. While this represents a surface for indirect prompt injection, it is assessed as safe within the context of the skill's intended professional use.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:50 AM
Security Audit — agent-trust-hub — bind-recon