skills/tonone-ai/tonone/deal-recon/Gen Agent Trust Hub

deal-recon

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Uses shell commands including find, grep, and xargs to locate files containing keywords like pipeline, revenue, and customer data. This is confined to searching for business-relevant files.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes data from untrusted local files (e.g., Markdown, CSV, and JSON files) during its reconnaissance phase. It lacks explicit boundary markers or content sanitization, though this is a common characteristic of data-processing skills.
  • [COMMAND_EXECUTION]: References a vendor-specific command /atlas-report for delivering detailed findings, which aligns with the author's established ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:57 AM
Security Audit — agent-trust-hub — deal-recon