agent-session-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill proactively defines security guardrails by instructing the agent to redact secrets from logs and code snippets, and to avoid committing sensitive files like
.envor private keys. - [SAFE]: The Git and PR policy enforces user oversight by requiring explicit confirmation for commits, pushes, and pull request creation, preventing unauthorized changes to the codebase.
- [SAFE]: The version check protocol utilizes a standard, non-executable command (
npm view) to query version metadata from the public NPM registry, which is a safe method for update notification. - [INDIRECT_PROMPT_INJECTION]: The skill builds context from external sources like the
.opencode/.kit-versionfile and general project structure, creating a minor surface for indirect prompt injection if those files are maliciously modified. - Ingestion points: Reads project-specific metadata from
.opencode/.kit-versionand performs analysis of the local project directory to build a session mental model. - Boundary markers: None identified for the ingested project metadata.
- Capability inventory: The skill uses shell command execution (
npm view) to check for package updates. - Sanitization: No explicit sanitization or validation of the version string is defined before comparison.
Audit Metadata