session-brain

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the obsidian-wiki CLI tool to perform data processing, clustering, and naming operations on session history. It also uses the open command to display a generated HTML graph in the user's browser.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes all historical session transcripts and history files, which constitutes an attack surface for indirect prompt injection. Malicious content from past conversations could potentially influence the agent during the cluster naming and summarization phase.
  • Ingestion points: Reads all files in ~/.claude/ (transcripts) and the history.jsonl file.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are used when the agent processes cluster top_terms and exemplars derived from the raw transcripts.
  • Capability inventory: The skill can execute shell commands via obsidian-wiki, write files to the ~/.claude/session-brain/ directory, and invoke the system's open command.
  • Sanitization: No sanitization or filtering of the session transcript content is performed before the data is summarized by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:26 AM
Security Audit — agent-trust-hub — session-brain