shell-history-hygiene
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
atuincommand-line utility and a local bash script to audit shell history. These operations are limited to stats gathering and dry-run comparisons. - [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it ingests shell history, which is external and potentially untrusted data.
- Ingestion points: Shell history is read via
atuinand saved to preview filesatuin-prune-preview-YYYY-MM-DD.txtandatuin-dedup-preview-YYYY-MM-DD.txt. - Boundary markers: None are explicitly used in the preview files to delimit history content from agent instructions.
- Capability inventory: The skill executes shell scripts and creates local files, but lacks network capabilities for exfiltration.
- Sanitization: The skill does not sanitize the history content, but its dry-run-only design ensures that even if malicious commands were present in the history, they would not be executed automatically by the agent.
- [SAFE]: The skill includes robust safety features, including the use of
--dry-runflags for all history operations and a requirement for the human user to manually copy and execute any cleanup commands. This 'kill-switch' design prevents accidental or malicious history loss.
Audit Metadata