toil-mining
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-supplied session logs in JSONL format to identify toil candidates.
- Ingestion points:
scripts/recent_human.py(line 123) reads raw data from session files provided via command-line arguments. - Boundary markers: The script uses
# My request for Codex:as a marker to isolate user requests and applies regex patterns inMACHINE_ECHO_PATTERNSto filter out machine-generated content. - Capability inventory: The skill uses the extracted data to score and rank tasks, and it has the capability to write output reports to the
.agents/scratch/toil-mining/directory. - Sanitization: The script normalizes whitespace and line endings but does not sanitize the extracted text for malicious instructions that might target the agent's behavior during the analysis phase.
- [COMMAND_EXECUTION]: The test suite utilizes shell command execution to verify the functionality of the extraction script.
- Evidence:
tests/test_recent_human.py(line 39) usessubprocess.runto call the Python interpreter and executescripts/recent_human.pywith specific test parameters. This is limited to the testing environment and uses programmatically defined arguments.
Audit Metadata