specstory-session-summary
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from SpecStory session history files, which serves as an ingestion point for untrusted data that could contain malicious instructions.
- Ingestion points: The skill reads markdown files located in the
.specstory/history/directory using shell commands liketailandgrepas described inSKILL.mdandreferences/session-parsing.md. - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the ingested session files, which could lead the agent to follow instructions found in the logs rather than summarizing them.
- Capability inventory: The skill uses shell tools to execute commands (
ls,grep,tail) and has the capability to read any file within the history directory. - Sanitization: No sanitization or validation of the content read from the history files is implemented, relying on the LLM's internal safety filters to handle potentially adversarial text.
Audit Metadata