schedule
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill's primary function is to create recurring or one-time scheduled tasks via the
create_scheduled_tasktool, allowing autonomous prompt execution at future intervals. - [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to distill the current session history into a prompt for future autonomous runs, creating a surface for persisting potentially malicious instructions.
- Ingestion points: The agent is instructed in
SKILL.mdto review the current session history, which may contain untrusted data from previously accessed files, websites, or tool outputs. - Boundary markers: The skill does not provide instructions to include boundary markers or "ignore embedded instructions" warnings in the newly generated prompt.
- Capability inventory: Future runs of the distilled prompt will have access to the agent's environment and tools (e.g., file system access, network operations).
- Sanitization: There are no instructions to sanitize or validate the content extracted from the session history before it is incorporated into the persistent, reusable prompt.
Audit Metadata