skills/tonone-ai/tonone/frame-board/Gen Agent Trust Hub

frame-board

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.
  • Ingestion points: The skill reads project documents and external web data via WebFetch (SKILL.md, Step 1).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard potential instructions in the source data.
  • Capability inventory: The skill is authorized to use Bash, Write, and WebFetch tools.
  • Sanitization: There is no instruction to sanitize or validate the content retrieved from external sources before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 10:45 AM
Security Audit — agent-trust-hub — frame-board