managing-context-sessions

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from files within a repository, creating a surface for indirect prompt injection attacks.
  • Ingestion points: The agent reads index.md, session files (<NN>-<slug>.md), and any repository source files identified by pointers in references/continuing-session.md and references/session-contract.md.
  • Boundary markers: The instructions do not define clear delimiters or warnings to ignore instructions embedded within the processed repository content or session entries.
  • Capability inventory: The skill possesses the ability to read and write files within the repository and execute shell-based commands such as git log and git status.
  • Sanitization: There is no evidence of content sanitization, escaping, or validation of the data retrieved from external files before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute Git commands to manage session context.
  • In references/continuing-session.md, the agent is instructed to run git log --name-only <sha>..HEAD to identify changes made since the last recorded entry.
  • In references/updating-session.md, the agent is instructed to use git status --porcelain and git log to collect information about changed files and sections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 12:20 AM
Security Audit — agent-trust-hub — managing-context-sessions