skills/tonone-ai/tonone/lens-metrics/Gen Agent Trust Hub

lens-metrics

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to assist users in defining metrics and implementing them via SQL. The instructions provided are professional, technical, and aligned with the stated purpose.
  • [COMMAND_EXECUTION]: The skill utilizes tools like 'Bash', 'Grep', and 'Glob' to scan the local workspace for data infrastructure (database configs, ORM files, dbt projects). This activity is scoped to discovery for schema understanding and is a standard requirement for generating accurate analytics queries within a development environment.
  • [DATA_EXFILTRATION]: While the skill accesses configuration files to understand data models, there are no instructions or patterns that indicate the transmission of sensitive data to external or untrusted domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from existing workspace files (SQL views, tracking plans, and documentation). While this presents a potential attack surface for indirect prompt injection if those files are malicious, the risk is inherent to the workspace-discovery capability and the skill does not exhibit dangerous autonomous behavior with this data.
  • [METADATA_POISONING]: A version mismatch exists between the 'SKILL.md' (0.6.4) and 'plugin.json' (1.9.1). This appears to be a documentation inconsistency rather than a deceptive or malicious pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — lens-metrics