skills/tonone-ai/tonone/folk-org/Gen Agent Trust Hub

folk-org

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are entirely focused on organizational design and management consultancy. No evidence of malicious intent, credential theft, or unauthorized network activity was found.- [PROMPT_INJECTION]: The skill has a vulnerability surface for indirect prompt injection because it ingests untrusted user input to define the company's organizational context.\n
  • Ingestion points: User-provided answers to context questions in Step 0 (SKILL.md).\n
  • Boundary markers: Absent; there are no instructions to the agent to ignore potential instructions embedded in the provided org chart or hiring data.\n
  • Capability inventory: Read, Bash, Glob, Grep (as defined in allowed-tools).\n
  • Sanitization: Absent; the skill does not include steps to filter or validate user-provided context for potential injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — folk-org