skills/tonone-ai/tonone/multi-recon/Gen Agent Trust Hub

multi-recon

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of processing untrusted external data.
  • Ingestion points: The skill reads Infrastructure-as-Code (IaC) configurations, service inventories, and architecture documentation in Step 1.
  • Boundary markers: There are no explicit instructions or delimiters defined to separate user-provided data from agent instructions or to warn the agent against executing commands found within those files.
  • Capability inventory: The skill is authorized to use Bash, Write, and WebFetch tools, which could be targeted by instructions embedded in the analyzed data.
  • Sanitization: The instructions do not specify any validation or sanitization for the content of the documents being gathered.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:50 AM
Security Audit — agent-trust-hub — multi-recon