session-governance-audit

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell and git commands to verify claims made in session transcripts. These include git log, git show, test -f, and grep. These are used for validation purposes within the scope of the auditing task.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data including session transcripts and task plans. It lacks specific instructions for the agent to distinguish between data content and instructions, creating a surface for injection attacks.
  • Ingestion points: The skill reads session transcript (JSONL/markdown) and originating task list documents.
  • Boundary markers: None. There are no explicit instructions to use delimiters or ignore embedded instructions within the processed transcripts.
  • Capability inventory: The agent can read the filesystem, execute git commands, create files, and commit changes to the repository.
  • Sanitization: None. The skill does not define methods for escaping or validating the content of the transcripts before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — session-governance-audit