skills/tonone-ai/tonone/terms-recon/Gen Agent Trust Hub

terms-recon

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose of drafting legal and privacy documentation.
  • [PROMPT_INJECTION]: The skill analyzes local documents and web content, which presents a surface for indirect prompt injection. (1) Ingestion points: SKILL.md reads project files and fetches web data. (2) Boundary markers: Absent. (3) Capability inventory: Bash, Write, and WebFetch tools are available. (4) Sanitization: None mentioned. This is a functional requirement for research-based tasks and no active exploits were found.
  • [COMMAND_EXECUTION]: The skill has access to shell commands via the Bash tool to perform file discovery and reconnaissance. This is a standard capability for development-oriented agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:50 AM
Security Audit — agent-trust-hub — terms-recon