skills/tonone-ai/tonone/forge-recon/Gen Agent Trust Hub

forge-recon

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple reconnaissance commands using established cloud CLIs (gcloud, aws, flyctl, wrangler). These are used for their primary intended purpose of infrastructure inventory.
  • [COMMAND_EXECUTION]: It uses local shell commands (find, ls, cat) to detect Infrastructure-as-Code (IaC) files such as Terraform, Pulumi, and Docker Compose.
  • [DATA_EXPOSURE]: The skill intentionally scans for potential credential leaks in IaC files (API keys, secrets) to flag them as critical security risks for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — forge-recon