skills/tonone-ai/tonone/form-mobile/Gen Agent Trust Hub

form-mobile

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, such as unauthorized network connections to unknown domains, hardcoded credentials, or persistence mechanisms, were detected in the skill's instructions or configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection. It is instructed to fetch and analyze external data (design systems, brand context, and style references) via WebFetch or user input. This data is then processed in an environment where the agent has access to powerful tools such as Bash, Write, and Edit. There are no instructions for the agent to use boundary markers or to ignore embedded instructions within these external materials.
  • Ingestion points: Phase 1 (Discovery) processes user-supplied brand context, logos, and existing design systems, and utilizes WebFetch to explore visual references.
  • Boundary markers: Absent. The instructions do not define delimiters (e.g., XML tags) or specific prompts to compartmentalize untrusted data from the agent's core logic.
  • Capability inventory: The skill's configuration enables Bash, Write, Edit, WebFetch, and WebSearch tools.
  • Sanitization: Absent. No explicit sanitization, validation, or filtering of the content retrieved from external design documents is specified.
  • [METADATA_POISONING]: A version discrepancy was observed between SKILL.md (0.6.4) and plugin.json (1.9.1). While this is common in development, inconsistent metadata can be a sign of poor maintenance or attempts to obfuscate the skill's actual update history.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — form-mobile