managing-context-sessions
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from files within a repository, creating a surface for indirect prompt injection attacks.
- Ingestion points: The agent reads
index.md, session files (<NN>-<slug>.md), and any repository source files identified by pointers inreferences/continuing-session.mdandreferences/session-contract.md. - Boundary markers: The instructions do not define clear delimiters or warnings to ignore instructions embedded within the processed repository content or session entries.
- Capability inventory: The skill possesses the ability to read and write files within the repository and execute shell-based commands such as
git logandgit status. - Sanitization: There is no evidence of content sanitization, escaping, or validation of the data retrieved from external files before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute Git commands to manage session context.
- In
references/continuing-session.md, the agent is instructed to rungit log --name-only <sha>..HEADto identify changes made since the last recorded entry. - In
references/updating-session.md, the agent is instructed to usegit status --porcelainandgit logto collect information about changed files and sections.
Audit Metadata