skills/tonone-ai/tonone/crest-okr/Gen Agent Trust Hub

crest-okr

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) as it processes untrusted user data alongside powerful tools.
  • Ingestion points: Strategic context, company stage, and North Star metrics are provided by the user in SKILL.md.
  • Boundary markers: None present; the skill does not use delimiters or instructions to isolate user-provided data from system instructions.
  • Capability inventory: The skill is authorized to use Bash, Write, Edit, WebFetch, and WebSearch (SKILL.md).
  • Sanitization: No validation or sanitization mechanisms are defined for the external data it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — crest-okr