skills/tonone-ai/tonone/helm-recon/Gen Agent Trust Hub

helm-recon

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the Bash tool to find and list markdown files and search for specific product-related keywords. The commands in SKILL.md are static and limited to environment reconnaissance.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads and processes the content of untrusted local markdown files found during the discovery phase. An attacker could embed malicious instructions within these documents.
  • Ingestion points: Local markdown files (*.md) in various project directories like docs/, research/, and briefs/.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to distinguish between file content and agent instructions.
  • Capability inventory: The skill is allowed to use Bash, WebFetch, WebSearch, and Read tools.
  • Sanitization: There is no evidence of sanitization or filtering of the content retrieved from external files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — helm-recon