skills/tonone-ai/tonone/brace-recon/Gen Agent Trust Hub

brace-recon

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute find and grep commands to locate support-related files like documentation and SLAs. These are standard search operations for discovery.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface (Category 8) as it reads content from discovered local files.
  • Ingestion points: Markdown, YAML, and JSON files matching support keywords found in the project directory.
  • Boundary markers: None present to distinguish file content from agent instructions.
  • Capability inventory: Access to tools including Bash, Read, WebFetch, and WebSearch.
  • Sanitization: No sanitization of the content from the audited files is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:57 AM
Security Audit — agent-trust-hub — brace-recon