skills/sethgammon/citadel/schedule/Gen Agent Trust Hub

schedule

Fail

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: HIGHCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes node scripts/local-schedule.js via shell to manage task persistence.
  • [COMMAND_EXECUTION]: User-supplied intervals and commands are interpolated into shell command strings (e.g., node scripts/local-schedule.js add "<expr>" "<command>"), which creates a risk of command injection if inputs are not properly sanitized by the underlying script.
  • [NO_CODE]: The referenced script scripts/local-schedule.js is missing from the skill bundle, preventing a full security audit of how it manages system-level persistence and input validation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 5, 2026, 10:50 AM