skills/tonone-ai/tonone/form-exam/Gen Agent Trust Hub

form-exam

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external content, such as website URLs and source code, to perform design audits. This ingestion path creates a surface for indirect prompt injection where malicious instructions could be embedded within the design data being analyzed.
  • [COMMAND_EXECUTION]: The skill's configuration includes the Bash tool in its allowed-tools list. While no malicious shell commands are present in the provided instructions, the availability of a shell environment alongside the processing of external data represents a capability that requires the agent to maintain strict adherence to its primary task.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — form-exam