asciinema-cast-format

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides bash templates that use variable interpolation (e.g., $TARGET_TIME) within shell arithmetic and jq filters. These patterns could be susceptible to command injection if the input variables are not properly validated before execution.\n- [PROMPT_INJECTION]: The skill processes data from external .cast files, which presents a surface for indirect prompt injection.\n
  • Ingestion points: Reads recording.cast (SKILL.md).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Uses Bash to execute jq, tail, sort, uniq, date, and bc on file contents.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 09:52 AM