shell-history-hygiene

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the atuin command-line utility and a local bash script to audit shell history. These operations are limited to stats gathering and dry-run comparisons.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it ingests shell history, which is external and potentially untrusted data.
  • Ingestion points: Shell history is read via atuin and saved to preview files atuin-prune-preview-YYYY-MM-DD.txt and atuin-dedup-preview-YYYY-MM-DD.txt.
  • Boundary markers: None are explicitly used in the preview files to delimit history content from agent instructions.
  • Capability inventory: The skill executes shell scripts and creates local files, but lacks network capabilities for exfiltration.
  • Sanitization: The skill does not sanitize the history content, but its dry-run-only design ensures that even if malicious commands were present in the history, they would not be executed automatically by the agent.
  • [SAFE]: The skill includes robust safety features, including the use of --dry-run flags for all history operations and a requirement for the human user to manually copy and execute any cleanup commands. This 'kill-switch' design prevents accidental or malicious history loss.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — shell-history-hygiene