rate-limit-recovery

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs broad file system reads across sensitive user directories to find session data and logs. Evidence: rate_limit_recovery.py accesses paths like ~/.codex, ~/.claude, ~/.pi, ~/.antigravity, and ~/.config/gcloud/logs.
  • [COMMAND_EXECUTION]: The skill executes external commands and local scripts to gather state and manage memory. Evidence: rate_limit_recovery.py uses subprocess.run to call curl for local database queries and to execute ~/.pi/skills/memory/memory.py.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing untrusted data from log files and session histories without sanitization. 1. Ingestion points: rate_limit_recovery.py reads data from numerous files in platforms' configuration and session directories. 2. Boundary markers: Absent. Collected content is not wrapped in protective delimiters or warnings to ignore embedded instructions. 3. Capability inventory: The skill can execute shell commands via subprocess.run, write report files, and trigger the external memory skill. 4. Sanitization: Absent. Content is read and interpolated into summaries and reports as raw text strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — rate-limit-recovery