skills/tonone-ai/tonone/touch-recon/Gen Agent Trust Hub

touch-recon

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a variety of Bash commands (e.g., ls, find, cat, grep) to perform environment detection and project analysis. These operations are diagnostic in nature and restricted to scanning the local project environment for standard mobile development artifacts like package.json, Podfile, and CI/CD configurations.
  • [DATA_EXFILTRATION]: While the instructions prompt the agent to identify authentication patterns and API integration details (e.g., token storage, base URLs), these activities are aligned with the stated purpose of application assessment and 'takeover' (project onboarding). No hardcoded credentials, malicious network requests, or exfiltration paths to unauthorized domains were detected.
  • [PROMPT_INJECTION]: The skill defines a specific persona ('Touch — the mobile engineer') and provides structured instructions for reconnaissance. There are no patterns observed that attempt to bypass safety filters, extract system prompts, or override agent behavior maliciously.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project files (e.g., build scripts and dependency locks). While these represent a potential surface for indirect injection if a project file were to contain malicious instructions, the skill does not currently implement specific boundary markers. However, given the diagnostic nature of the tool, the risk remains low and consistent with standard developer utility behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — touch-recon