skills/tonone-ai/tonone/serv-design/Gen Agent Trust Hub

serv-design

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted workload descriptions and requirements from users which are then processed to generate technical designs and IaC scaffolds using powerful tools.
  • Ingestion points: User-provided workload context, traffic patterns, and latency requirements gathered in Step 1.
  • Boundary markers: Absent. The instructions do not provide delimiters or 'ignore embedded instructions' warnings for the agent when processing user data.
  • Capability inventory: Access to Bash, Write, WebFetch, and WebSearch tools as defined in the SKILL.md frontmatter.
  • Sanitization: Absent. There is no explicit validation or escaping of external content before it is interpolated into the agent's reasoning or output generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:50 AM
Security Audit — agent-trust-hub — serv-design