skills/tonone-ai/tonone/warden-harden/Gen Agent Trust Hub

warden-harden

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands (grep, cat, ls) to identify project frameworks and existing security configurations. These are standard reconnaissance steps for a security auditing tool and are used within a restricted scope.
  • [EXTERNAL_DOWNLOADS]: The skill references standard security auditing tools such as npm audit, pip-audit, govulncheck, and trivy. These are well-known industry-standard tools for dependency and container vulnerability scanning.
  • [DATA_EXFILTRATION]: While the skill searches for hardcoded secrets (e.g., in .env files or using process.env), its instructions focus on moving these secrets to secure management systems (AWS/GCP Secret Manager, Vault) and ensuring they are not committed to source control. There is no evidence of sending this sensitive data to external or untrusted domains.
  • [PROMPT_INJECTION]: The skill adopts a 'security engineer' persona ('Warden') to guide its operations, but it does not attempt to bypass platform safety guidelines or override system constraints. The instructions are focused on providing and implementing defensive security measures.
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference to an external organization 'tonone-ai' (the author) in the metadata and configuration. This is treated as a vendor resource and is documented neutrally without escalating the verdict.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — warden-harden