transcript-promotion
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from session transcripts (.jsonl files) which contain historical interaction data. While the extraction logic targets assistant-type messages, these messages may contain content or instructions originally supplied by users or external sources in previous turns. The skill enforces verbatim extraction without sanitization or boundary markers, creating a potential for malicious instructions from previous sessions to be persisted into durable plan files that influence future agent behavior. * Ingestion points: Reads from transcript files in the ~/.claude/projects/ directory. * Boundary markers: Absent; the skill explicitly requires verbatim extraction to maintain the audit trail. * Capability inventory: The skill can write new files to ~/.claude/plans/, modify git repositories, and execute shell commands via chezmoi and other system tools. * Sanitization: Absent; extraction is performed without filtering for potentially malicious instructions.
- [COMMAND_EXECUTION]: The skill executes shell scripts (extract-anchor-range.sh and propagate-via-chezmoi.sh) that wrap system utilities such as jq, grep, sed, awk, git, and chezmoi. These scripts are used to slice transcript data and synchronize files with local and remote version control repositories.
Audit Metadata