skills/tonone-ai/tonone/pave-env/Gen Agent Trust Hub

pave-env

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its reliance on external project documentation to guide its behavior.
  • Ingestion points: The agent is instructed to read content from untrusted local files including README.md, CONTRIBUTING.md, and various environment configuration files (e.g., docker-compose.yml, Vagrantfile) to identify necessary services and setup steps.
  • Boundary markers: The instructions do not provide delimiters or safety warnings to the agent to treat data found in these external files as potentially untrusted, increasing the risk that the agent may follow malicious instructions embedded in a project's documentation.
  • Capability inventory: The skill is granted high-privilege tool access, including Bash for shell command execution and Write/Edit for modifying the filesystem.
  • Sanitization: There is no evidence of content sanitization or validation performed on the data ingested from project files before it influences the agent's actions or command generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — pave-env