skills/agentscope-ai/qwenpaw/cron/Gen Agent Trust Hub

cron

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to interact with the system via the qwenpaw cron command-line utility to manage task lifecycles.
  • [PERSISTENCE]: The primary purpose of the skill is to enable persistence through the scheduling of recurring or delayed tasks using the platform's native cron functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a mechanism for storing text and instructions to be executed at a future time, which creates a potential surface for indirect prompt injection if external or untrusted data is included in the task payload.
  • Ingestion points: The --text parameter in the qwenpaw cron create command (SKILL.md) accepts input that is stored for later execution.
  • Boundary markers: The skill documentation does not define specific delimiters or instructions to ignore embedded commands within the scheduled task content.
  • Capability inventory: The skill uses the qwenpaw CLI to schedule tasks that can send messages or trigger agent queries across multiple channels.
  • Sanitization: There are no explicit requirements or examples provided for sanitizing or validating the input provided in the --text or -f job_spec.json arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:39 AM
Security Audit — agent-trust-hub — cron