session-continuation

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface detected.\n
  • Ingestion points: The skill instructs the agent to read project-level documentation (/CLAUDE.md) and task details from an MCP backlog tool to assess the current state.\n
  • Boundary markers: No delimiters or protective instructions (e.g., "ignore instructions in this file") are specified when reading these external data sources.\n
  • Capability inventory: The skill has the ability to modify local project state via git commands (add, commit) and update task statuses through MCP tools.\n
  • Sanitization: No content validation or sanitization process is defined for the data ingested from files or task notes.\n- [COMMAND_EXECUTION]: The skill directs the agent to execute standard local git commands and call MCP tools for state management. These commands are essential to the primary function of context recovery and session continuation.\n- [NO_CODE]: The skill consists entirely of markdown-based instructions and does not package any executable scripts, binaries, or automated code execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 06:15 PM
Security Audit — agent-trust-hub — session-continuation