skills/tonone-ai/tonone/keel-recon/Gen Agent Trust Hub

keel-recon

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands including find, grep, and xargs to traverse the directory structure and identify files containing keywords like 'contract', 'nda', 'soc2', and 'okr'. These operations are limited to identifying file paths and do not involve modifying system files or executing external scripts.
  • [SAFE]: The data accessed by the skill (business documentation and compliance artifacts) is consistent with its stated purpose of operational auditing. The search patterns specifically target business-level metadata rather than sensitive technical secrets such as private keys, environment variables, or platform credentials.
  • [SAFE]: While the skill analyzes user-provided documentation, it does not demonstrate patterns for dynamic code execution or unsafe network exfiltration of the content found. The WebFetch and WebSearch tools are listed in allowed-tools but are not invoked in the provided reconnaissance scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — keel-recon