skills/simhacker/moollm/time/Gen Agent Trust Hub

time

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE] (SAFE): The skill core logic focuses on narrative time management and state synchronization. It correctly differentiates between simulation turns and LLM response cycles. No evidence of malicious command execution or data exfiltration was found across the analyzed files.
  • [Indirect Prompt Injection] (SAFE): The skill features a data ingestion surface where it interprets natural language durations (e.g., 'Wait until morning'). Evidence: 1. Ingestion points: WAIT command parameter in CARD.yml and GLANCE.yml. 2. Boundary markers: Absent. 3. Capability inventory: read_file and write_file (limited to tier 1). 4. Sanitization: Absent. While this is an attack surface, the low-privilege nature of the allowed tools and the lack of execution capabilities render the risk negligible.
  • [Metadata Poisoning] (SAFE): Metadata in SKILL.md and CARD.yml is consistent with the skill's stated purpose and does not contain deceptive instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:36 PM