skills/tonone-ai/tonone/volt-firmware/Gen Agent Trust Hub

volt-firmware

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation and design tool for embedded systems. It guides the agent to produce structured C header stubs, state tables, and memory budgets based on user requirements.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted 'device descriptions' from users. While it has access to capabilities like Bash and Write, the instructions are strictly focused on design and documentation output. It lacks explicit boundary markers for user input, representing a minor surface for indirect injection that is common in creative or technical drafting skills.
  • [COMMAND_EXECUTION]: The skill includes Bash in its allowed-tools. It references an internal reporting command /atlas-report for handling large outputs. Given the author context (tonone-ai), this appears to be a vendor-specific tool for data presentation and does not represent an external attack vector.
  • [SAFE]: The 'Security Baseline' section promotes industry best practices for target devices, such as secure boot, TLS 1.2+, and anti-rollback mechanisms, indicating a security-conscious design.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — volt-firmware