time-report
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted conversation transcript files (JSONL) from Claude Code, Cursor, Codex, and Pi. These files contain arbitrary text from previous AI interactions which could contain malicious instructions designed to influence the agent during the time-reporting phase.
- Ingestion points: Transcript files located in
~/.claude/,~/.cursor/,~/.codex/, and~/.pi/are read byscripts/scan-sessions.ts. - Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the processed transcripts.
- Capability inventory: The skill uses
gh pr viewvia shell command and potentially logs data to Jira, providing a pathway for exfiltration or state change if an injection is successful. - Sanitization: While it uses Zod for schema validation of the JSON structure, it does not sanitize the internal NL content of the messages for potential injection patterns.
Audit Metadata