continuity-ledger

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to find recent directories and determine the project root. It also runs a local script scripts/core/artifact_mark.py using uv run to record session outcomes. These commands are restricted to the local filesystem and project-specific tooling provided by the vendor.
  • [INDIRECT_PROMPT_INJECTION]: The skill automates the creation of a continuity ledger by summarizing session activities into a YAML format for use in subsequent sessions.
  • Ingestion points: Data is ingested from the active session context, task history, and user responses within SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the session data being written into the YAML fields.
  • Capability inventory: The skill has the capability to write to the filesystem and execute local project scripts (SKILL.md).
  • Sanitization: The skill lacks explicit sanitization or escaping mechanisms for session content before it is interpolated into the ledger, which could allow malicious instructions encountered during a session to be persisted and acted upon in a later session.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — continuity-ledger