skills/tonone-ai/tonone/serv-recon/Gen Agent Trust Hub

serv-recon

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, such as obfuscation, persistence, or data exfiltration, were detected. The tools requested, including Bash and WebFetch, are appropriate for the skill's stated purpose of auditing infrastructure and performance.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it is instructed to read and process untrusted external data in the form of infrastructure-as-code (IaC) definitions and serverless configurations. 1. Ingestion points: Step 1 (Lambda/Cloud Function configs and IaC definitions). 2. Boundary markers: None specified in the instructions to separate data from instructions. 3. Capability inventory: Bash, Glob, Grep, Write, and WebFetch tools. 4. Sanitization: No sanitization or validation of the ingested configuration content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — serv-recon