temporal-awareness

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The script scripts/capture_temporal_context.py retrieves system metadata to establish a session anchor. This includes the machine's hostname via socket.gethostname(), platform information via platform.platform(), and local timezone configurations by reading the /etc/localtime symlink. This data is collected to provide context for temporal grounding and is not exfiltrated to external services.
  • [INDIRECT_PROMPT_INJECTION]: The scripts/recency_guard.py script serves as a classification engine for untrusted user input.
  • Ingestion points: The script accepts raw user text via the --prompt CLI argument.
  • Boundary markers: None are explicitly enforced in the script arguments; the agent is instructed to pass user prompts directly for analysis.
  • Capability inventory: The skill possesses capabilities for reading system clock data, identifying timezones, and directing the agent to perform web searches for live verification. It does not contain direct shell execution or file-writing capabilities beyond stdout reporting.
  • Sanitization: The script performs regex-based classification to identify volatile domains (e.g., stocks, CEOs, laws) and relative time markers. While it does not sanitize or escape the input string, the input is only used for pattern matching and is not executed or interpreted as code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — temporal-awareness