agent-history

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and display past conversation history through commands like ochist grep and ochist part. Because this history originates from prior sessions that may have included content from untrusted external sources (such as web summaries or processed files), it serves as a potential vector for malicious instructions to be re-injected into the current session.
  • Ingestion points: Conversation history is retrieved from local data stores via the ochist CLI in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or warnings to separate historical content from current instructions during retrieval.
  • Capability inventory: The agent is encouraged to use shell tools (grep, awk, jq) and the node runtime to process this data.
  • Sanitization: No explicit sanitization, filtering, or validation of the historical text is mentioned prior to the agent reading the full message content.
  • [COMMAND_EXECUTION]: The skill documents and provides usage patterns for the ochist command-line interface. It includes instructions for piping output through standard shell utilities and suggests executing the tool directly via node <repo>/dist/cli.js if the binary is not available in the system PATH.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 04:36 PM