skills/tonone-ai/tonone/helm/Gen Agent Trust Hub

helm

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by passing user-provided arguments directly to sub-skills.
  • Ingestion points: User input is ingested via the {{args}} parameter in SKILL.md.
  • Boundary markers: There are no explicit delimiters (e.g., XML tags or triple quotes) used to isolate the user input from the routing instructions.
  • Capability inventory: The skill's environment allows access to tools such as Bash, Write, Edit, WebFetch, and WebSearch as specified in the allowed-tools metadata.
  • Sanitization: The skill does not perform pre-processing or validation on the {{args}} content before passing it to the Skill tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:57 AM
Security Audit — agent-trust-hub — helm