closeout
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several shell commands to manage the environment, including
git status,ls,git branch, andgit log. These are used to inventory session activity and verify the state of the repository. - [COMMAND_EXECUTION]: It invokes local tools and scripts such as
~/.local/bin/claude-md-autogen-gate,organvm context sync, andorganvm refresh. These tools are part of the vendor's ecosystem and are used to verify and update project metadata. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes files authored or modified during the session to determine their closure status, which introduces an attack surface for indirect prompt injection.
- Ingestion points: Reads markdown plans from
~/.Codex/plans/*.mdand structured data fromdata/prompt-registry/prompt-atoms.jsonto identify status references such asDONE-NNNorIRF-XXX-NNN. - Boundary markers: There are no explicit boundary markers or instructions to ignore potential commands embedded within the session plans being analyzed.
- Capability inventory: The skill has capabilities to create and modify files, move plan files to an abandoned directory, and execute shell commands (
git,ls,mv,organvm). - Sanitization: Content from the analyzed files is not sanitized or validated before being processed to determine the session's completion state.
Audit Metadata