continuity-ledger
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to find recent directories and determine the project root. It also runs a local script
scripts/core/artifact_mark.pyusinguv runto record session outcomes. These commands are restricted to the local filesystem and project-specific tooling provided by the vendor. - [INDIRECT_PROMPT_INJECTION]: The skill automates the creation of a continuity ledger by summarizing session activities into a YAML format for use in subsequent sessions.
- Ingestion points: Data is ingested from the active session context, task history, and user responses within
SKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the session data being written into the YAML fields.
- Capability inventory: The skill has the capability to write to the filesystem and execute local project scripts (
SKILL.md). - Sanitization: The skill lacks explicit sanitization or escaping mechanisms for session content before it is interpolated into the ledger, which could allow malicious instructions encountered during a session to be persisted and acted upon in a later session.
Audit Metadata