skills/tonone-ai/tonone/flux-recon/Gen Agent Trust Hub

flux-recon

Fail

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to check for connection strings in sensitive files known to store plain-text credentials.
  • Evidence: SKILL.md specifies checking for connection strings in .env, database.yml, settings.py, and config/ directories.
  • [DATA_EXFILTRATION]: The skill combines the ability to read sensitive files with tools like WebFetch and Bash, which can be used to send extracted credentials to external servers.
  • Evidence: Allowed tools include Read, Bash, and WebFetch alongside instructions to find credentials in environment files.
  • [COMMAND_EXECUTION]: The skill grants the agent Bash access to perform the reconnaissance, allowing for arbitrary command execution on the host system to inspect database files and application code.
  • Evidence: Bash is listed in allowed-tools for environment detection and schema analysis.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — flux-recon