skills/0xr3ngar/bstack/time-report/Gen Agent Trust Hub

time-report

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted conversation transcript files (JSONL) from Claude Code, Cursor, Codex, and Pi. These files contain arbitrary text from previous AI interactions which could contain malicious instructions designed to influence the agent during the time-reporting phase.
  • Ingestion points: Transcript files located in ~/.claude/, ~/.cursor/, ~/.codex/, and ~/.pi/ are read by scripts/scan-sessions.ts.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the processed transcripts.
  • Capability inventory: The skill uses gh pr view via shell command and potentially logs data to Jira, providing a pathway for exfiltration or state change if an injection is successful.
  • Sanitization: While it uses Zod for schema validation of the JSON structure, it does not sanitize the internal NL content of the messages for potential injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 08:22 PM