session-loop

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run various system commands (e.g., git, kubectl, helm, terraform) to perform drift checks and verify the environment state. These operations are core to the skill's purpose as a project management and migration toolkit.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing data from project-local files which could theoretically be manipulated to influence agent behavior.\n
  • Ingestion points: NEXT_SESSION.md, UPDATES.md, and discovered project ledgers (e.g., DECISIONS.md) are read by sub/catchup.md, sub/drift.md, and sub/open-loops.md.\n
  • Boundary markers: Absent; the instructions do not specify delimiters or safety warnings when reading external artifact content.\n
  • Capability inventory: Across its scripts, the skill utilizes subprocess calls for git, kubectl, helm, az, gh, terraform, dig, and pgrep (sub/drift.md, sub/wrap.md).\n
  • Sanitization: Absent; the agent is directed to re-run verification commands directly as extracted from the artifacts.\n- [SAFE]: The installation script (install.sh) performs standard symlinking of skill files into agent-specific directories without downloading external payloads or requesting elevated privileges.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 12:20 PM
Security Audit — agent-trust-hub — session-loop