skills/tonone-ai/tonone/warden-recon/Gen Agent Trust Hub

warden-recon

Warn

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is explicitly instructed to inventory and read sensitive files, including .env files and configurations for secrets managers like GCP Secret Manager, AWS Secrets Manager, Vault, and Doppler.
  • [DATA_EXFILTRATION]: The instructions direct the agent to search for hardcoded secrets in source code and check CI/CD environments for secret injection methods.
  • [DATA_EXFILTRATION]: The skill includes instructions to bypass local output limits by invoking an external command ('/atlas-report') with the 'full findings,' which includes the sensitive data inventoried during the reconnaissance phase. This pattern can facilitate data exfiltration if the reporting tool is not properly sandboxed.
  • [COMMAND_EXECUTION]: The skill utilizes the 'Bash' tool to perform environment detection, list service accounts, and review permissions. It executes shell commands to inspect configuration files such as Terraform state, Kubernetes manifests, and cloud-provider-specific setup.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it reads and processes untrusted data from project files (lock files, dependencies, and configuration manifests) without explicit boundary markers or sanitization, potentially allowing malicious content in those files to influence the agent's behavior.
  • [PROMPT_INJECTION]: The skill instructs the agent to 'never dump analysis to CLI' and instead use an external reporting mechanism. This concealment pattern reduces user oversight of the data being collected and transmitted.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — warden-recon